A report on Chinese digital surveillance and hacking of Uyghurs
1–10 of 14 posts
Re: A report on Chinese digital surveillance and hacking of Uyghurs
#2 The exploit itself is 22,963 bytes of code and if successful will ultimately result in the forced download of a file name loader to the /data/data/com.android.browser directory of the victim device
How can a website force download a file to a device? Seems like a browser vulnerabilityRe: A report on Chinese digital surveillance and hacking of Uyghurs
#3The exploit itself is 22,963 bytes of code and if successful will ultimately result in the forced download of a file name loader to the /data/data/com.android.browser directory of the victim device How can a website force download a file to a device? Seems like a browser vulnerability
But for instance all images, many pages, etc are locally stored/cached by the browser.
Re: A report on Chinese digital surveillance and hacking of Uyghurs
#4The exploit itself is 22,963 bytes of code and if successful will ultimately result in the forced download of a file name loader to the /data/data/com.android.browser directory of the victim device How can a website force download a file to a device? Seems like a browser vulnerability
Mmhh.. browsers cache things. When they do, they write things to disk- not sure if that is relevant here though. But for instance all images, many pages, etc are locally stored/cached by the browser.
Re: A report on Chinese digital surveillance and hacking of Uyghurs
#5The exploit itself is 22,963 bytes of code and if successful will ultimately result in the forced download of a file name loader to the /data/data/com.android.browser directory of the victim device How can a website force download a file to a device? Seems like a browser vulnerability
Volexity has identified similarities to but has not yet verified that the exploit being employed in this attack is the Chrome Turbofan remote code execution vulnerability that was reported via the SecuriTeam Secure Disclosure program and is covered in an advisory here: https://ssd-disclosure.com/archives/3379/ssd-advisory-chrome...
Re: A report on Chinese digital surveillance and hacking of Uyghurs
#6So either that Xinjiang province is not behind the great firewall, or that Xinjiang has far greater internet freedom than the rest of China, so which one is which? You can't really have both in this case.
Re: A report on Chinese digital surveillance and hacking of Uyghurs
#7I am gonna have to call BS on this report. Everyone knows that google including gmail is blocked in China, so why would they try to get a hold of their google oauth? Additionally, I just went onto one of the mentioned websites at random, turkistantimes.com and guess what, the site is hosted in the America, in Houston! So either that Xinjiang province is not behind the great firewall, or that Xinjiang has far greater…
If you're targeting activists inside of China you have to expect they'll use those VPNs. You also expect them to specifically choose non-chinese mail/communication mediums in order to not be identified by the PRC.
This report is newsworthy because it says that making these choices might not protect you anymore.
Re: A report on Chinese digital surveillance and hacking of Uyghurs
#8I am gonna have to call BS on this report. Everyone knows that google including gmail is blocked in China, so why would they try to get a hold of their google oauth? Additionally, I just went onto one of the mentioned websites at random, turkistantimes.com and guess what, the site is hosted in the America, in Houston! So either that Xinjiang province is not behind the great firewall, or that Xinjiang has far greater…
China is targeting Uighurs that have moved out of China: the "Uighur diaspora".
When you smell bullshit, always double check your assumptions, sometimes the smell is coming from nearer than you might think!
Re: A report on Chinese digital surveillance and hacking of Uyghurs
#9The exploit itself is 22,963 bytes of code and if successful will ultimately result in the forced download of a file name loader to the /data/data/com.android.browser directory of the victim device How can a website force download a file to a device? Seems like a browser vulnerability
Re: A report on Chinese digital surveillance and hacking of Uyghurs
#10I am gonna have to call BS on this report. Everyone knows that google including gmail is blocked in China, so why would they try to get a hold of their google oauth? Additionally, I just went onto one of the mentioned websites at random, turkistantimes.com and guess what, the site is hosted in the America, in Houston! So either that Xinjiang province is not behind the great firewall, or that Xinjiang has far greater…