Live data from Hacker News

A report on Chinese digital surveillance and hacking of Uyghurs

volexity.com

1–10 of 14 posts

Re: A report on Chinese digital surveillance and hacking of Uyghurs

#2

   The exploit itself is 22,963 bytes of code and if successful will ultimately result in the forced download of a file name loader to the /data/data/com.android.browser directory of the victim device
How can a website force download a file to a device? Seems like a browser vulnerability

Re: A report on Chinese digital surveillance and hacking of Uyghurs

#3
post #2

The exploit itself is 22,963 bytes of code and if successful will ultimately result in the forced download of a file name loader to the /data/data/com.android.browser directory of the victim device How can a website force download a file to a device? Seems like a browser vulnerability

Mmhh.. browsers cache things. When they do, they write things to disk- not sure if that is relevant here though.

But for instance all images, many pages, etc are locally stored/cached by the browser.

Re: A report on Chinese digital surveillance and hacking of Uyghurs

#4
post #3
post #2

The exploit itself is 22,963 bytes of code and if successful will ultimately result in the forced download of a file name loader to the /data/data/com.android.browser directory of the victim device How can a website force download a file to a device? Seems like a browser vulnerability

Mmhh.. browsers cache things. When they do, they write things to disk- not sure if that is relevant here though. But for instance all images, many pages, etc are locally stored/cached by the browser.

k, wasn't meaning the cache. I'm assuming android doesn't go randomly loading stuff out of the cache

Re: A report on Chinese digital surveillance and hacking of Uyghurs

#5
post #2

The exploit itself is 22,963 bytes of code and if successful will ultimately result in the forced download of a file name loader to the /data/data/com.android.browser directory of the victim device How can a website force download a file to a device? Seems like a browser vulnerability

From the article:

Volexity has identified similarities to but has not yet verified that the exploit being employed in this attack is the Chrome Turbofan remote code execution vulnerability that was reported via the SecuriTeam Secure Disclosure program and is covered in an advisory here: https://ssd-disclosure.com/archives/3379/ssd-advisory-chrome...

Re: A report on Chinese digital surveillance and hacking of Uyghurs

#6
I am gonna have to call BS on this report. Everyone knows that google including gmail is blocked in China, so why would they try to get a hold of their google oauth? Additionally, I just went onto one of the mentioned websites at random, turkistantimes.com and guess what, the site is hosted in the America, in Houston!

So either that Xinjiang province is not behind the great firewall, or that Xinjiang has far greater internet freedom than the rest of China, so which one is which? You can't really have both in this case.

Re: A report on Chinese digital surveillance and hacking of Uyghurs

#7
post #6

I am gonna have to call BS on this report. Everyone knows that google including gmail is blocked in China, so why would they try to get a hold of their google oauth? Additionally, I just went onto one of the mentioned websites at random, turkistantimes.com and guess what, the site is hosted in the America, in Houston! So either that Xinjiang province is not behind the great firewall, or that Xinjiang has far greater…

Specialized VPNs (SS/SSR) are a common way to work around the GFW to get worldwide internet access.

If you're targeting activists inside of China you have to expect they'll use those VPNs. You also expect them to specifically choose non-chinese mail/communication mediums in order to not be identified by the PRC.

This report is newsworthy because it says that making these choices might not protect you anymore.

Re: A report on Chinese digital surveillance and hacking of Uyghurs

#8
post #6

I am gonna have to call BS on this report. Everyone knows that google including gmail is blocked in China, so why would they try to get a hold of their google oauth? Additionally, I just went onto one of the mentioned websites at random, turkistantimes.com and guess what, the site is hosted in the America, in Houston! So either that Xinjiang province is not behind the great firewall, or that Xinjiang has far greater…

"However, each of the compromised websites are banned by the great firewall in China, leaving largely only those outside of the country as targets and potential victims."

China is targeting Uighurs that have moved out of China: the "Uighur diaspora".

When you smell bullshit, always double check your assumptions, sometimes the smell is coming from nearer than you might think!

Re: A report on Chinese digital surveillance and hacking of Uyghurs

#9
post #2

The exploit itself is 22,963 bytes of code and if successful will ultimately result in the forced download of a file name loader to the /data/data/com.android.browser directory of the victim device How can a website force download a file to a device? Seems like a browser vulnerability

That's why it's called an exploit

Re: A report on Chinese digital surveillance and hacking of Uyghurs

#10
post #6

I am gonna have to call BS on this report. Everyone knows that google including gmail is blocked in China, so why would they try to get a hold of their google oauth? Additionally, I just went onto one of the mentioned websites at random, turkistantimes.com and guess what, the site is hosted in the America, in Houston! So either that Xinjiang province is not behind the great firewall, or that Xinjiang has far greater…

The oppressed minorities in China have to use VPNs, and China has shown repeatedly that they do not limit cyber attacks to their own territories. In Sweden a very small, local newspaper argued that Taiwan should be recognized as a proper country in the WHO. China made a formal request to the Swedish Ministry of Foreign Affairs that the journalist and publisher should be condemned (I work for the publisher), and that the ministry should publish a "correction" in said newspaper. We refused and the ministry also refused. The newspaper's site has been DDOS:ed sporadically for months now after that and this attack shows no signs of stopping. I believe in coincidences, but I don't believe this is a coincidence.
Post reply on HN