Live data from Hacker News

The Great Cannon has been deployed again

cybersecurity.att.com

51–60 of 470 posts

Re: The Great Cannon has been deployed again

#51
post #10

I've wondered about this, in the years since. Does anyone else have a sense of what (if any) pragmatic technical steps could effectively deter or neuter this tactic? If the network can't demonstrate the ability to at least pump the brakes on this, it's hard to imagine other states or even the owners of large safe-monopoly ISPs won't get a little jealous of the tool.

Block all traffic from China?

Re: The Great Cannon has been deployed again

#52
post #37

Earlier quoted context omitted.

I think the primary argument line is something along: 1. Online ads today are so bad they must be blocked 2. But blocking ads blocks revenue for sites we like 3. So we should pay for them more directly 4. But I'm not about to set up 100 different monthly subscriptions. These corporations are not trustworthy and I cannot monitor this many bills. 5. We need a solution to simplify money -> content -> creator transfer 6.…

Serve content related ads and don't track. I'd be fine with that.

Same. But I think that once you've screwed the pooch this bad, you can't just take a single step backwards and expect everyone to be fine with that. The trust is gone. You've got to reboot and rebrand somehow.

Re: The Great Cannon has been deployed again

#54
post #2

This is a good counter example for whenever you find yourself in an argument with anti-adblocker folks.

But these folks still have no answer for how free websites they consume daily (e.g. news) are to be funded, they don't pay, and don't want to see ads either. Yet they still expect these websites to exist. I use Firefox's built Enhanced Tracking Prevention, that some sites call "ad blocking" but in reality it is super easy to have ads that don't get blocked by it, just make them non-creepy.

> But these folks still have no answer for how free websites they consume daily (e.g. news) are to be funded, they don't pay, and don't want to see ads either.

It's not a question they need to answer, that's the problem of the companies that caused this mess.

> Yet they still expect these websites to exist.

Not really, they just use what exists, not what they expect to exist.

Re: The Great Cannon has been deployed again

#55
post #6

I didn’t see this anywhere in the article (maybe I missed it), but because this utilizes the Great Firewall, it’s undoubtedly done by the Chinese government, right?

No. "Behind the Great Firewall" is another way of saying "served from China". Perhaps -- or even most likely -- it is the government. But this is hardly a smoking gun. There are plenty of people on the mainland that hate what's going on in HK, and who are not the government.

> There are plenty of people on the mainland that hate what's going on in HK, and who are not the government.

AFAIK, those people are generally not capable of performing a MITM attack on traffic coming from sources inside China.

Re: The Great Cannon has been deployed again

#56
post #27

Earlier quoted context omitted.

It always bothers me when I hear people say this, it's everyone's responsibility that their devices don't become part of a botnet or worse used to take part in an attack against infrastructure that we're increasingly dependent upon that either makes for an unpleasant time for people or threatens lives.

99.9% of devices are owned by someone who has absolutely zero technical ability to fulfill this responsibility. So I'd say the responsibility needs to be satisfied another way. Maybe it escalates to the ISP. I mean, unless we start issuing Internet Licenses the way we do Driver's Licenses. In the early 2000s my cable provider would outright shut off our Internet if my dumb brother or my dumb self got us all virused u…

I agree, most don't have the technical ability to administrate their devices although I'm not sure if that excuses basic competence. I like the idea that an ISP would disable the connection of a subscriber however that would depend on how they define malicious activity.

Re: The Great Cannon has been deployed again

#57
post #30

Earlier quoted context omitted.

baidu.com is not distributing the script. A proxy is taking advantage of unsecure connections (http) to serve the malicious script instead of baidu's script.

It's 2019, what excuse does Baidu have to not support https for these scripts?

If you are pro-interrupt-private-transactions then you are in no hurry to push https on everyone.

Re: The Great Cannon has been deployed again

#58
post #49
post #30

Earlier quoted context omitted.

It's 2019, what excuse does Baidu have to not support https for these scripts?

It's not a matter of excuses. Baidu, like almost all large Chinese companies, is effectively an arm of the Chinese Communist Party. They will do as they're told.

Which is exactly why Baidu should face the same consequences as other malware distributors. (i.e. safebrowsing block, dnsbl listings and so on)

Re: The Great Cannon has been deployed again

#59
post #56

Earlier quoted context omitted.

99.9% of devices are owned by someone who has absolutely zero technical ability to fulfill this responsibility. So I'd say the responsibility needs to be satisfied another way. Maybe it escalates to the ISP. I mean, unless we start issuing Internet Licenses the way we do Driver's Licenses. In the early 2000s my cable provider would outright shut off our Internet if my dumb brother or my dumb self got us all virused u…

I agree, most don't have the technical ability to administrate their devices although I'm not sure if that excuses basic competence. I like the idea that an ISP would disable the connection of a subscriber however that would depend on how they define malicious activity.

If ISPs were basic utilities it would probably be a fairly safe responsibility to give them. But no, they're media corporations, so they have an inherent drive to abuse that power.

Re: The Great Cannon has been deployed again

#60
post #37

Earlier quoted context omitted.

I think the primary argument line is something along: 1. Online ads today are so bad they must be blocked 2. But blocking ads blocks revenue for sites we like 3. So we should pay for them more directly 4. But I'm not about to set up 100 different monthly subscriptions. These corporations are not trustworthy and I cannot monitor this many bills. 5. We need a solution to simplify money -> content -> creator transfer 6.…

Serve content related ads and don't track. I'd be fine with that.

Don’t track. Serve ads in a designated space across all pages (sidebar). I personally would happily uninstall adblocker if those two things came true.
Post reply on HN