So if the cannon is created using the great firewall, how does the Chinese government establish any sort of plausible argument that this isn't state-sponsored activity? Do they just not care? Some day soon a war will not be started with an assassins bullet but with a tool like this. I wonder when we start looking at them the same way?
The Great Cannon has been deployed again
411–420 of 470 posts
Re: The Great Cannon has been deployed again
#412Earlier quoted context omitted.
> Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on the net. But that is literally what web users want . Everything you named is a fine opinion, but runs contrary to the wishes of the vast majority of millions and millions and millions and millions of web users. EDIT: That said, browsers have features for users such as yourself to…
> But that is literally what web users want. No it absolutely does not. Just because a user doesn't understand what Javascript is or how to diagnose why their computer is slow (is it an app, website, update, virus etc) does not imply consent. Pretty sure that most people just want to be able to visit a website without it causing problems to their computer or to others.
Re: The Great Cannon has been deployed again
#413Browsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on…
For china need some way to handle that whole commerical-military-party all one entity.
Re: The Great Cannon has been deployed again
#414So, maybe firewall off China for a couple of days? Sure, it would hurt on both sides but at least it would be clear that abuse at this scale leads to being blackholed.
I agree that such bad behavior should be punished, but why just couple of days? This would be similar to UN trade sanctions that are imposed on bad state actors. I think we generally overestimate the hurt on the outside and underestimate the hurt on the inside considering the massive trade imbalance that China enjoys with the rest of the world. Personally I have already pi-holed entire .cn and other domains.
UN sanctions are not imposed on bad state actors. They are imposed on weak state actors. UN sanctions have never been imposed on the US, China, Russia, Britain and France easily the worst state actors globally - the biggest weapons sellers and the cause of instability all over the world. They also are the 5 permanent security council members with veto power.
> I think we generally overestimate the hurt on the outside and underestimate the hurt on the inside considering the massive trade imbalance that China enjoys with the rest of the world.
China doesn't enjoy a trade imbalance with the "rest of the world". The enjoy it with the US primarily. They are net importers of Japan, South Korea, Saudi Arabia, Brazil, etc.
Germany, Japan, South Korea, etc also enjoy trade imbalance with the "rest of the world". Do you support sanctioning them?
> Personally I have already pi-holed entire .cn and other domains.
That doesn't do much if you really think about it. It's not like chinese individual, company or government are barred from owning everything from coms to orgs.
Re: The Great Cannon has been deployed again
#415Earlier quoted context omitted.
Yes, who cares about the forced labor camps and suicide nets around factories. I want my cheap plastic consumer devices!!
> Yes, who cares about the forced labor camps and suicide nets around factories. Nobody really cares, except for those directly involved. Sad but true, nobody will ever go to war for that, for foreign citizens. > I want my cheap plastic consumer devices!! People do actually want that. And their cheap shoes and clothes and...
Re: The Great Cannon has been deployed again
#416Earlier quoted context omitted.
You do know you’re suggesting that sites not be able to load assets from other sites right?
They are specifically suggesting that HTTP-only sites not be able to load from third party sites, which is quite a bit different than your interpretation of generally preventing any site from loading any external content. HTTPS ought to be the default and browsers can, and should, move towards that. But to answer your question more directly, yes they clearly know what they are suggesting.
Highly unlikely, or else the suggestion would be to just ban http all-together. Http without the ability to load resources from other domains would break the majority of sites.
Re: The Great Cannon has been deployed again
#417Browsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on…
This sounds like a knee-jerk reaction that doesn't take into consideration the ramifactions of the suggested policy. It won't stop DDoS attacks, because those exist _because the internet exists_ and unless you dismantle the very concept of interconnected "everyone can reach everyone" networking, all you're doing is locking down access to more and more people until only technical experts or the people with enough mone…
I haven't noticed NoScript distinguish between http and https sources for javascript, but perhaps I don't visit sites that pull in javascript via http.
Re: The Great Cannon has been deployed again
#418Earlier quoted context omitted.
Well, with the rise of anti DDoS services meaning the targeted websites are staying online, rendering the “Great Cannon” more like a pathetic peashooter, that’s doing one thing. Calling China out whenever they do this is another. Unmask the Chinazis for what they are.
I don't think that last line is helpful. If you believe that the Chinese government is akin to the Nazi party, better to make the argument explicitly than to use a term like "Chinazis", which could be interpreted as overly broad and highly insulting in the best case.
Re: The Great Cannon has been deployed again
#419Earlier quoted context omitted.
They are specifically suggesting that HTTP-only sites not be able to load from third party sites, which is quite a bit different than your interpretation of generally preventing any site from loading any external content. HTTPS ought to be the default and browsers can, and should, move towards that. But to answer your question more directly, yes they clearly know what they are suggesting.
I note this language in the writeup: > These attacks would not be successful if the following resources were served over HTTPS instead of HTTP: > http://push.zhanzhang.baidu.com/push.js ; or > http://js.passport.qihucdn.com/11.0.1.js This seems overly generous. I personally would not assume that the government of China couldn't persuade Baidu or qihucdn.com to serve government-provided JavaScript. It also assumes tha…
Re: The Great Cannon has been deployed again
#420Earlier quoted context omitted.
General Aviation; the same people that lobby to keep using leaded fuels.
That's a bit too harsh. The GA people are lobbying to continue to be able to fly their aircraft. The FAA has been sitting on the problem of non-leaded avgas for something like 30 years now. The GA people don't like being exposed to lead any more than anyone else.