5 ms·
Chinese govt is also capable of doing this. Best part? We even have our trusted* root certificate! Could this get any "better"? Sure! We can even MITM all the
by dujiulun2006 11y ago
Chinese govt is also capable of doing this. Best part? We even have our trusted* root certificate!
Could this get any "better"? Sure! We can even MITM all the OUTGOING https traffic if we want! #GitHubDDoS
* Recently un-trusted by Apple and Mozilla. https://support.apple.com/en-us/HT204938 https://support.apple.com/en-us/HT204938
- orf 11y agoTo be fair they really fucked up a couple of stages of that GitHub DDOS and made it trivial to stop.
- jacquesm 11y agoAnd they managed to shine the spotlight on a project in need of some tlc.
- duncan_bayne 11y agoI really don't understand how that sort of behaviour doesn't constitute an act of war. Imagine if China sent saboteurs in-country to physically destroy infrastructure being used by American businesses. That would Not Be Taken Lightly.
- cortesoft 11y agoWhich sort of behavior? Having their own root certificate?
- duncan_bayne 11y agoI meant China's behaviour, e.g. orchestrating a DDOS attack against GitHub for political reasons. The root certificate thing is 'merely' a violation of the rights of their own subjects.
- cortesoft 11y agoAh, ok that makes more sense.
- com_kieffer 11y agoThe same way that Stuxnet destroying Iranian centrifuges was an act of war ?
- duncan_bayne 11y agoYes. Although I'd have thought that particular war would have started back with the hostage-taking in, what, 1979? I really don't understand relationships between States.
- mil0 11y agoalways love a good reference to Argo.
- ta0o0o0 11y agoI'm not a West Hater by any means, but I'd say the war started when the US and the UK engineered a coup in Iran because Iran nationalized their oil industry (after the British oil company running it refused to be audited or to renegotiate terms). https://en.wikipedia.org/wiki/1953_Iranian_coup_d'%C3%A9tat https://en.wikipedia.org/wiki/1953_Iranian_coup_d'%C3%A9tat
- duncan_bayne 11y agoWhereas I'd say the problem was forced nationalisation.
- antocv 11y agoWhereas I'd say the problem was forced privatization/colonization.
- lhopki01 11y agoA foreign coup is a valid response to nationalisation?
- duncan_bayne 11y ago
- peteretep 11y ago> how that sort of behaviour doesn't constitute an act of war You need photos of explosions and dead babies to convince your populace to go to war. Making a case for war between nuclear powers on the basis that "some website for geeks became a bit less reliable" isn't going to cut it.
- andreyf 11y agoWas that trusted root cert ever misused? IIRC, it was un-trusted because they did not do their due diligence on how an issued sub-cert was being used by an Egyptian company. What does the GitHub DDOS have to do with MITM attacks on https?
- mil0 11y agothe ddos was achieved by altering the contents of one of the script on a large chinese site (was it baidu? google it). Once every user on that site loaded the tampered script, it made sure to send many requests to github.
- therein 11y agoWas the large Chinese site serving traffic over HTTPS?
- dujiulun2006 11y agoSadly, they (Baidu) are not, which is why the script content was easily modified. To clear it up, I said that GFW "can" do (but has not yet done) these. But it tried to MITM some https traffic earlier with a non-trusted certificate as an experiment.
- andreyf 11y agoExperiment? This isn't science. They can ask any engineer what MITM with a non-trusted cert would do, and that's nothing.
- dujiulun2006 11y ago@andreyf: More like a social experiment. See whether people would notice (we did) and what's their reaction.