22 ms·
The Great Cannon has been deployed again
- brenden2 7y agoThis is a good counter example for whenever you find yourself in an argument with anti-adblocker folks.
- euroclydon 7y agoWhy? The Great Cannon is served from a proxy. It can inject whatever it wants. It doesn’t have to swap out ad tracker JS.
- myself248 7y agoOr "Why should I care about security, I have nothing of value" folks. You do have something of value: Bandwidth.
- e2le 7y agoIt always bothers me when I hear people say this, it's everyone's responsibility that their devices don't become part of a botnet or worse used to take part in an attack against infrastructure that we're increasingly dependent upon that either makes for an unpleasant time for people or threatens lives.
- Waterluvian 7y ago99.9% of devices are owned by someone who has absolutely zero technical ability to fulfill this responsibility. So I'd say the responsibility needs to be satisfied another way. Maybe it escalates to the ISP. I mean, unless we start issuing Internet Licenses the way we do Driver's Licenses. In the early 2000s my cable provider would outright shut off our Internet if my dumb brother or my dumb self got us all virused up.
- e2le 7y agoI agree, most don't have the technical ability to administrate their devices although I'm not sure if that excuses basic competence. I like the idea that an ISP would disable the connection of a subscriber however that would depend on how they define malicious activity.
- Waterluvian 7y agoIf ISPs were basic utilities it would probably be a fairly safe responsibility to give them. But no, they're media corporations, so they have an inherent drive to abuse that power.
- kortilla 7y agoWhat you’re describing as “basic competence”, which is removing viruses from a PC in this case, would exclude 99% of users.
- nradov 7y agoA responsibility is meaningless if most people have no practical means to exercise that responsibility.
- hombre_fatal 7y agoOne step in the right direction is to drop the marketing bullshit of "unlimited internet" (which doesn't exist) and always meter it, but make it completely transparent. If your smart toaster is saturating your bandwidth, it should show up as an expensive line-item on your bill. You should see that "SmartToast9000" used $80 of bandwidth, "baidu.com" used $17 because it used your bandwidth to ddos. And, of course, the tooling to catch these things before they escalate would likely become part of our computing devices. Right now, everything is completely opaque to the end-user and we all suffer except for bad actors. It's a problem when we can't even estimate how much bandwidth we used in a month off the top of our head. Instead it should be informing our decisions from the IoTrash we buy to which websites we use. Example: the internet was regularly awful at my girlfriend's house. We couldn't figure it out despite calling the ISP. On a suspicion, I helped my gf install a bandwidth monitor on her laptop. We found that a recipes website she often had open would get stuck in some sort of ad-loading retry loop due to her adblocker and would saturate her download bandwidth as long as she had it open. It's completely ridiculous to me that there's no feedback built in to the browser when I think it should be a first-class UI component. I think transparent + metered bandwidth (at a fair price of course) would start the ball rolling on this kind of tooling. Until then, it's like everything acts like bandwidth is unlimited.
- MisterTea 7y agoThis is a tiring example of why the web and all its technologies thoroughly suck. It's a boiling toilet fueled by greed.
- fredley 7y agoAnd yet here you are. I'm interested how you would perceive something that might supercede the internet by being better (than a boiling toilet fueled by greed), ignoring network effects?
- SmellyGeekBoy 7y agoSomething similar to the web in the late 90s / early 2000s?
- Gh0stRAT 7y agoThe Internet of the early 2000s was consumed by greed. What changes would you make to its replacement to prevent the exact same pattern from repeating?
- MisterTea 7y agoExactly what I'm thinking. Not everything is awful but the insistence of turning the browser into a vm and loading random javascript is pure insane. I'm not advocating for stoneage html and frames but let's take a step back and realize that not every website has to be an interactive webpage some designer dreamed up. I want information, not entertainment or an experience. The experience is what I take away from the information, not the clown paint smeared all over it for show.
- icandoit 7y agoEveryone has to be somewhere. I would not be surprised to find someone, who feels like the modern internet as it exists is terrible, on hacker news. I believe the sentiment is more common here than say, the comments section on CNN. I like the approach taken by the folks at the dat project and beaker browser. Let's make the web a DHT already. If we can force consumers to share what they consume then a DDOS becomes impractical for censoring speech (the speech spreads all over the network, making it counterproductive).
- Someone1234 7y agoBut these folks still have no answer for how free websites they consume daily (e.g. news) are to be funded, they don't pay, and don't want to see ads either. Yet they still expect these websites to exist. I use Firefox's built Enhanced Tracking Prevention, that some sites call "ad blocking" but in reality it is super easy to have ads that don't get blocked by it, just make them non-creepy.
- andrewprock 7y agoOn the contrary, people pay for Netflix. People also pay for the ad-free upgrade to Hulu. Speaking to text websites, people are also using Brave, though I don't know how that experiment will work out in the end.
- Someone1234 7y agoI think Brave is on the right track, but I am skeptical the kind of users that are aggressively anti-ad are going to like seeing ads straight in their notifications. I'd prefer to just pay Brave e.g. $10/month and have it give out that money to sites I visit.
- csunbird 7y agoWhen it is reasonably priced, people will pay for legal alternatives. If there was a Netflix for paid websites, which would provide subscriptions in a convenient way to all websites in bulk, people would pay for that. Current options are: > Manage subscriptions of 10 plus websites manually > Pay by your privacy It is clear that both options suck, so people opt in to ad blockers instead. Legal options are just overpriced for the demand.
- kevin_thibedeau 7y agoAd blocking is not illegal.
- hombre_fatal 7y agoI think we need a solution for websites that aren't as unanimously popular as Netflix and Hulu. It's no surprise to me that the biggest entertainment services online can attract a subscription. But it would be a damn shame if those are the only services that can make much money. Just more and more centralization of content. People often respond to this with "well, hobbyists make plenty of content for free," but the thing is that we benefit when our favorite hobbyists can make money from the craft and produce more work for us to enjoy instead of waiting around for their charity. Though the growth of Patreon is a good step in the right direction, culturally. It shows a growing willingness to indeed pay content producers directly with small recurring transactions.
- jefftk 7y agoThis is not a good counterexample: the attacker is only able to do this because the analytics scripts are being served over HTTP. If you include the analytics on your site over HTTPS this sort of attack is not relevant.
- ninkendo 7y agoI imagine China has quite a bit of infrastructure to push their own CA's onto devices in china, enough to do any MITM'ing they want.
- mminer237 7y agoThe Chinese government has the root certificates for every Chinese certificate authority. It can MITM traffic for any citizen, even over HTTPS.
- jefftk 7y agoWhat makes this attack powerful is not that sites within China can be shut down (the government can already do that) but that sites outside of China can be tricked into DDOSing other sites outside of China. Which is why this attack only works over HTTP.
- saagarjha 7y agoRight, but the traffic is coming from users in China is past the point that HTTPS would help. The requests are already in flight from people in China who've been served malicious JavaScript.
- mminer237 7y agoWhat I mean is that China can just force a CA to give the CPC its root certificate and then just intercept and edit any HTTPS responses to Chinese citizens and resign them as secure.
- inimino 7y agoIt would work just as well over HTTPS, they would just have to make a different phone call (to the site hosting the script rather than to the GFW).
- fortytw2 7y agoI didn’t see this anywhere in the article (maybe I missed it), but because this utilizes the Great Firewall, it’s undoubtedly done by the Chinese government, right?
- nradov 7y agoThat's the implication but as with most cyber attacks it's impossible to really prove the source.
- dannyw 7y agoThis is one of the cyber attacks where the source is proven.
- nradov 7y agoWe all know who the attacker is here, but it's not literally "proven" to the standard of evidence that would be required in a US court. The attacker still has plausible deniability.
- johncolanduoni 7y ago“Someone else who has the ability to MITM millions of users in China did it” doesn’t sound particularly plausible to me.
- simias 7y agoI know that this website is very USA-centric but I really fail to see what US courts have to do with the subject at hand. The question is more "as far as the international community is concerned, is there any reasonable technical doubt that the Chinese authorities are behind this?" This is important for public discourse at least, because if it's technically undeniable that Chinese authorities are behind this attack then you can immediately assume than anybody saying that China has nothing to do with it is either acting in bad faith or is largely uninformed. As we've seen multiple times in the past the existence or non-existence of conclusive proof is largely irrelevant when it comes to international policy anyway so the opinion of US courts is frankly besides the point.
- pkilgore 7y agoSo if the cannon is created using the great firewall, how does the Chinese government establish any sort of plausible argument that this isn't state-sponsored activity? Do they just not care? Some day soon a war will not be started with an assassins bullet but with a tool like this. I wonder when we start looking at them the same way?
- NedIsakoff 7y agoThe question is, you know I'm using it. Besides some words, what the heck are you going to do?
- eznoonze 7y agoThey don't care. It is of course state sponsored. The denial is just their way to fool their own people. The Chinese Communist Party rule by lies and violence. Those are the 2 keywords to understand CCP.
- faitswulff 7y agoDon't forget that the power behind the CCP's lies and violence is economic clout, both abroad and domestically.
- eznoonze 7y agoYes, absolutely. The economic clout gives them the confidence and means. That needs to be dealt with. Declaw!
- cc81 7y agoLike how the world dealt with the US after Snowden's reveals?
- microcolonel 7y agoThey were all doing the same and worse, it turns out. They could hardly complain. Americans must regain the courage and dignity of differing from the hundred lame, neoliberal, tacit fascist-enabling bugman regimes that litter the world. It's often good not to be like them.
- abathur 7y agoI've wondered about this, in the years since. Does anyone else have a sense of what (if any) pragmatic technical steps could effectively deter or neuter this tactic? If the network can't demonstrate the ability to at least pump the brakes on this, it's hard to imagine other states or even the owners of large safe-monopoly ISPs won't get a little jealous of the tool.
- revicon 7y agoBlock all traffic from China?
- hombre_fatal 7y agoA Hong Kong protest forum becoming inaccessible to Chinese users is the entire objective of the DDoS in the first place.
- olodus 7y agoIf you are a site aimed at people in Hong Kong (or elsewhere in China), that is not very helpful.
- gruez 7y agoCollateral damage aside, that doesn't really solve the issue. The attack goes something like this: 1. non-chinese user visits a chinese site 2. the traffic goes through the gfw, which inserts malicious javascript 3. the user executes the malicious javascript and starts ddosing the victim site Blocking chinese users won't help, since non-chinese visitors will still ddos your site.
- alfalfasprout 7y agoIf China is cut off, then people can't download the malicious JS either. Granted, it sets a pretty bad precedent and would have massive economic consequences.
- hombre_fatal 7y agoCentralize behind Cloudflare like everyone else.
- FDSGSG 7y agoIf baidu.com is distributing the script, why is baidu.com not being flagged as malware by the various mechanisms used to block this kind of nastiness? Are the vendors just cowards?
- CrazyStat 7y agobaidu.com is not distributing the script. A proxy is taking advantage of unsecure connections (http) to serve the malicious script instead of baidu's script.
- FDSGSG 7y agoIt's 2019, what excuse does Baidu have to not support https for these scripts?
- deleted 7y ago[deleted]
- CrazyStat 7y agoNone whatsoever.
- NedIsakoff 7y agoProbably because the government asked them not to.
- nradov 7y agoIt's not a matter of excuses. Baidu, like almost all large Chinese companies, is effectively an arm of the Chinese Communist Party. They will do as they're told.
- FDSGSG 7y agoWhich is exactly why Baidu should face the same consequences as other malware distributors. (i.e. safebrowsing block, dnsbl listings and so on)
- LatteLazy 7y agoI had no idea this thing existed but it's actually a smart and relatively straightforwards thing for the PRC to do, shitty as it is... I was especially impressed with their getting the target to retrieve, resize and transmit an image: that's a smart way to waste time...
- sgc 7y agoBrowsers should prompt user and require confirmation before sucking down resources repeatedly in this way. Especially since this is grabbing images/content that are then not going to be displayed.
- pysxul 7y agoI am still amazed by how genius of an idea this is to DDOS at large scale
- FDSGSG 7y agoThe RPS isn't that great compared to some IoT botnets and this also gives the attacker rather limited control over the requests. It's a cool idea but I'm not really convinced that it's actually worth the trouble. China has better tools, like XORDDoS.
- thepete2 7y agoIt's bad that there are enough plain http connections for this to be possible.
- deleted 7y ago[deleted]
- mminer237 7y agoAlthough Baidu does still default to HTTP, the Chinese government has the root certificates for every Chinese certificate authority. It can MITM traffic for anybody in China, even over HTTPS, so that wouldn't solve the problem.
- deleted 7y ago[deleted]
- cryptozeus 7y agoWow really? Any source for this ? That is like everyone can lock their house but gov has the master key.
- mminer237 7y agoI suppose I probably overstated the situation a bit. The PRC National Intelligence Law ( http://cs.brown.edu/courses/csci1800/sources/2017_PRC_NationalIntelligenceLaw.pdf http://cs.brown.edu/courses/csci1800/sources/2017_PRC_Nation... ) requires, "Any organization or citizen shall support, assist and cooperate with the state intelligence work...", and China was observed making its own certificates for foreign sites before this ( https://news.ycombinator.com/item?id=5124784 https://news.ycombinator.com/item?id=5124784 ), but there's no direct evidence that China actually has all the root certificates currently or has used them maliciously. Of course, the law requires citizens to preserve secrecy and Westerners can't observe what China is doing, so that wouldn't be unexpected.
- dehrmann 7y agoDo browsers and OSes trust Chinese CAs?
- blackearl 7y agohttps://outline.com/8BBX3b https://outline.com/8BBX3b due to obnoxious header and footer
- jacquesm 7y agoSo, maybe firewall off China for a couple of days? Sure, it would hurt on both sides but at least it would be clear that abuse at this scale leads to being blackholed.
- mminer237 7y agoLIHKG requires a Hong Kong ISP to register anyway, so it's not like that site blocking mainland China would hurt it at all.
- weberc2 7y agoI would rather see more rigorous trade policy. Frankly fewer low-quality or fraudulent Chinese imports will probably be a net positive and even if it is more expensive, I would rather our trade dollars support countries with less corrupt governments and better ethics with respect to intellectual property, fraud, environmental protection, etc. I’m sure this will garner plenty of whataboutism regarding how the west is imperfect (never minding that I didn’t say “the west”)...
- dmix 7y agoThe west is constantly pushing for stuff like this in every trade policy with China and others... There’s a limit to how much leverage any one side has on a sovereign countries policies (and how much they actually enforce them when they agree). There’s also the question of the benefits of having China at all in these deals, some concessions and a growing dependence on western markets from initial deals is better than no deals. Plus a wealthier China is good for the world and the billion people coming out of poverty, getting educated, and slowly becoming an advanced economy.
- weberc2 7y ago> There’s a limit to how much leverage any one side has on a sovereign countries policies (and how much they actually enforce them when they agree). I’m not advocating for anyone controlling sovereign Chinese policies. They can continue their awful anti-humanitarian policies, fraud, IP theft, etc. I just don’t want my country aiding and abetting it. At very least I want my fellow citizens to be able to make informed purchasing decisions. And I’m all for lifting people out of poverty, but I’d rather do it in a country with some minimum base line respect for human rights and integrity, and where my purchasing dollars don’t end up propping up some dictatorial system that bullies other countries.
- johnchristopher 7y ago"Across the Great Wall we can reach every corner in the world."
- gok 7y agoWhat exactly is the rest of the world getting from allowing China access to the Internet?
- dehrmann 7y agoAliExpress and TikTok.
- erikpukinskis 7y agoA foot in the door
- saagarjha 7y agoThe ability to communicate with hundreds of millions of people in China who have nothing to do with this?
- kortilla 7y agoDoesn’t seem worth it. Still have several billion living in countries that don’t actively damage the internet. Make do with communicating with them.
- yumraj 7y agoCan/shouldn't the rest of the world create a Greater firewall to block the traffic from China? Let China enjoy it's solitude and we'll enjoy our openness.
- rahuldottech 7y agoYeah except we will effectively be cutting off _all_ outside information from the Cinese citizens, who already have to face incredible amounts of censorship. Cut them off completely, and we will never find out about all the human rights violations taking place in their country, and their government will be able to brainwash its citizens even more easily.
- hamhand 7y agoDDoS attacks against business competitors are common and rarely punished in China. Injecting ads/affiliate or whatever js in webpages, stealing social media tokens to do follower boosting business and selling optic fiber traffic dump is also common for Chinese ISPs.
- branon 7y agoInteresting article, shame it happens to be on a site where undismissable hovering banners on the top and bottom of the screen gobble up 30% of real estate.
- SamuelAdams 7y ago> These attacks would not be successful if the following resources were served over HTTPS instead of HTTP: Can someone explain how using HTTPS would mitigate this attack?
- theptip 7y agoHTTPS makes a MiTM attack much harder, because you need to have a valid cert for the host you are spoofing.
- 3JPLW 7y agoDoesn't the Great Firewall mandate (or at least strongly suggest) that those Chinese-controlled root certs are installed for devices behind it?
- dehrmann 7y agoIf this were a root cert, OSes and browsers could ban that CA. If you want this to work with SSL, giving the Great Firewall a domain cert would be enough.
- cryptozeus 7y agoHttps is not hackable “yet” so you can’t intercept the traffic in the middle. They intercepted http traffic and swapped the malicious js file in http traffic.
- josefx 7y agoCan't China just issue its own certificates to make the browser see a secure connection to the target server when it talks to a Chinese firewall server instead. I mean they have access to valid root certificates, right?
- deleted 7y ago[deleted]
- Steltek 7y agoWhat DDoS protection are they using? AT&T didn't say other than it was present.
- saagarjha 7y agoI'd guess Cloudflare: $ nslookup -type=soa lihkg.com Server: 8.8.8.8 Address: 8.8.8.8#53 Non-authoritative answer: lihkg.com origin = kevin.ns.cloudflare.com mail addr = dns.cloudflare.com serial = 2032679273 refresh = 10000 retry = 2400 expire = 604800 minimum = 3600 Authoritative answers can be found from:
- jariel 7y agoIf a foreign nation disrupted any kind of local service it might be considered an act of war.
- nullc 7y agoThe web needs to start moving towards a strong same-origin policy for all embedded content-- require sites to proxy requests if they want third party content. The first step could be sending CORS preflight, then requiring it, then just not allowing cross origin to different domains (but allow sub-/sibling- domains).
- goalieca 7y agoThe problem right now is that the originating server sets an http response header. Given the MITM can modify that header.. it indicates things need to be done automagically in the browser. But that will break A LOT.
- cortesoft 7y agoNot sure how much that would help... they could just have their own domain be a cname to the target. Your defense idea might stop layer 7 attacks, but not lower level ones.
- 1shooner 7y agoHow would this be different than the CNAME cloaking[1] currently being used by data collectors to circumvent ad blocking software? 1. https://news.ycombinator.com/item?id=21604825 https://news.ycombinator.com/item?id=21604825
- mrgreenfur 7y agoI agree that this is the next step in the ad-tech / spy-tech war. uBlock recently found an approach for blocking cnamed origins: https://github.com/gorhill/uBlock/commit/3a564c199260a857f3d78d5f12b8c3f1aa85b865 https://github.com/gorhill/uBlock/commit/3a564c199260a857f3d...
- hinkley 7y agoAbout a month ago we were discussing this and a few of us came to the conclusion that an eventually-required CORS header for cross-origin GETs would be a good thing. CDNs and SSO services could start sending this header so they can stay in business when the browsers turn off all cross-origin requests by default. Unfortunately (from my perspective) that'll do nothing to stop third party ad tracking but you can't have everything, I suppose.
- nakedrobot2 7y agoA complete sanction of everything Chinese will soon be a talking point, campaign point, strategic possibility.
- ignoramous 7y ago> It is unlikely these sites will be seriously impacted. Partly due to LIHKG sitting behind an anti-DDoS service, and partly due to some bugs in the malicious Javascript code that we won’t discuss here. If I get the attack scenario right, valid user IPs from behind the great firewall are driving traffic to the webservers, and so what are some examples of anti-DDoS mitigations that are effective in filtering out the adversarial traffic?
- saagarjha 7y agoProbably whatever Cloudflare uses, like JavaScript challenges.
- ct520 7y agoand then the hacker news cannon took down att's site..
- crazygringo 7y agoI'm curious: is it technically and politically possible for the operators of all internet cables receiving traffic from China to filter out malicious scripts? AT&T's writeup says the injection is only possible because it's HTTP (not HTTPS), and that there are two specific JavaScript files which sometimes serve up the malicious code. So in case of known malware like this being served from within a geographic region... is there any way to filter this out at scale? Or is that computationally infeasible at scale, so it would have to be built into the browser or something? The article also doesn't make clear -- is this DDoS coming exclusively from outside of China? Or is it injecting the same malicious code inside of China as well, and they're just not bothering to distinguish between requests coming from inside or outside the country? (In which case, the DDoS will continue regardless, just not with the rest of the world's help.)
- spydum 7y agoI'm not a huge fan of anybody (china or otherwise) performing content inspection or filtering on my behalf transparently. That's just another instance of the Great Firewall with other people at the reigns. If you chose to do that at your edge network, kudos for you. Just don't force it upon me.
- gruez 7y ago>I'm curious: is it technically and politically possible for the operators of all internet cables receiving traffic from China to filter out malicious scripts? Considering that the halting problem is undecidable, it's impossible to filter out the malicious scripts with complete certainty. The best you can do is use blacklists/heuristics which lead to an arms race. >So in case of known malware like this being served from within a geographic region... is there any way to filter this out at scale? Or is that computationally infeasible at scale, so it would have to be built into the browser or something? foreign ISPs can block port80 or http requests from coming into china. sure, it's going to break a lot of sites, but it's relatively simple for any site to get unblocked - all they need to do is set up letsencrypt.
- mlyle 7y ago> Considering that the halting problem is undecidable, This doesn't mean that you can't prove a big subset of scripts safe. > The best you can do is use blacklists/heuristics which lead to an arms race. You can also allow the scripts that automatically prove safe, plus other popular scripts you decide to explicitly allow, plus other scripts that are low-rate enough that you don't believe them to be a concern.
- ai_ja_nai 7y agoHow about interrupting BGP traffic from/to China by nearby western AS everytime the Cannon is used?
- zer00eyz 7y agoWhat would happen if we black hole all of china's IP range from all over the USA? I suspect that a lot of businesses would flex muscle on both sides to get that to stop really quickly. It would be a hard policy to implement on our side, but likely very effective. Its almost like we need someone in power smart enough to ASK telco's and carriers to DO such a thing.
- upofadown 7y agoBrowsers really have to be a lot more skeptical about the code they run. Running code should not be able to randomly attack any IP address on the internet. Code from non-TLS pages should not be able to run at all. Perhaps that should also apply to code loaded from 3rd party sites. Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on the net. It certainly should not be consent to delegate that power to others, either via a embedded link or a MITM attack.
- saagarjha 7y ago> Running code should not be able to randomly attack any IP address on the internet. How would you prevent this? What constitutes an "attack", and how would you make sure you're not interfering with non-malicious use cases?
- Despegar 7y agoJavaScript was a mistake
- lonelappde 7y agoThis is a network protocol flaw not a language flaw
- hombre_fatal 7y agoThis is just another kneejerk. They could have just injected an <img> tag with randomized src="" directly.
- xorcist 7y agoThat would not consitute such a problem. The script is what provides the amplification factor here.
- kortilla 7y agoYou do know you’re suggesting that sites not be able to load assets from other sites right?
- dfawcus 7y agoThat page generates no response for me, https://archive.is/I1WO6 https://archive.is/I1WO6 does.
- degenerate 7y agoThanks. For others using CTRL+F to find this link, some keywords... [archive, site down, 404, error page, mirror] Edit: better/cleaner version: https://outline.com/8BBX3b https://outline.com/8BBX3b
- emilfihlman 7y agoProbably want to add the actual error code of 504 gateway timed out timeout
- DyslexicAtheist 7y agoThis should be mitigated by browser vendors by integrating HTTPSEverywhere as a core functionality of the browser that needs to be explicitly turned off (instead of the current state of affairs where we have a tiny minority on the web who are familiar with installing security add-ons). Visiting a HTTP site should come with a scary warning. I understand this throws old sites under the bus, but there could be other solutions here such as restricting 3d party resources as a second layer defense once the user clicks through the first warning to access the HTTP content. and in case I'm totally wrong, what mitigations are feasible? More trade war such as by compelling ISP's to null-route Chinese businesses like Baidu.com as a form of sanction?
- ghostly_s 7y agoI don't quite understand the mechanism after reading the article. Is the attacker (presumably the PRC) MITM'ing these CDN resources at the infrastructure level? If they had exploits in place within these CDNs (presumably within the PRC's capabilities) HTTPS wouldn't help, no?
- arcticbull 7y agoMore than likely they placed a phone call to Baidu and told them exactly what to do. I doubt it's a technological MITM probably just a social one. A totalitarian state can do that.
- DyslexicAtheist 7y agothat's why probably null routing at ISP level is more likely. the time it takes to adapt to new defenses is much less than what it takes to come to an agreement in cabforum. When things escalate nobody will push vendors to agree on new security features when a blunt instrument like legislation is cheaper. If things escalate they'll just sinkhole all traffic going in and out of China.
- lonelappde 7y agoThe article says only HTTP traffic is affected. If they subverted Baidu at the server side ,https traffic would likely be affected equally.
- GrumpyNl 7y agoi get a 500.
- bcoates 7y agoAm I the only one disappointed this wasn't about someone refurbishing the Dardanelles Gun?
- inimino 7y agoI see a lot of arguments for specific technical mitigations for the specific implementation of this attack. All these technical approaches are doomed to fail. The attack uses network-level injection to add malware to HTTP requests for resources served from inside China. This malware then runs on hosts anywhere in the world and effectively DDoSes the targets. It is true that if these specific requests were made over HTTPS rather than HTTP, this particular attack would be mitigated. Unfortunately the point that is being missed here is that if these resources had been served over HTTPS, this attack simply would have been implemented in a slightly different way. The suggested mitigations would work post-facto. However, if had they been in place prior to this attack, which is the alternative we have to consider, other means would have rendered them useless. The fact is that any website hosted in China is directly accessible to the CCP for hosting these attack payloads. There is an ICP registration system and a chain of access to hosting environments that grants full network control and full access to any server to the authorities at any time they choose. Servers that are not part of this system are simply not allowed to host websites on the Chinese internet. Further, there is direct political control over every major internet company. This is such a fundamentally different situation that it can be hard for American observers to understand what range of potential responses are meaningful. The reality is that any network request that is served from China is fully within the political power of the CCP to alter. Whether this involves HTTP or HTTPS or whether implemented via the GFW or by direct changes to endpoints within internet companies is immaterial. Beyond the logistical costs of these actions within China, nothing of any consequence is changed by such minor technical mitigations. What these attacks show is not just the capability but the willingness to use that capability in an offensive capacity against political targets. The difference between the internet of independent sites in the US and the situation of near-total political control over resources on the network in China can hardly be overstated. This is why technical solutions that seem completely reasonable from an American perspective are pointless in reality. The threat model of the world's largest online population with all network resources under direct political control is simply too unfamiliar. If the political will exists to use those resources offensively, technical countermeasures will always be ineffective, unless they are so seemingly disproportionate that they become essentially political acts, like depeering. Meaningful responses are those that affect the political willingness of the CCP to weaponize the internet. Weaponization will destroy the internet as we know it, and raising awareness before this kind of thing becomes routine may be the last chance we have to avoid it. This is a political problem, and does not have a technical solution.
- maxfan8 7y agoI'm not experienced in DDOS mitigation techniques, but is it possible to redirect malicious traffic to the malicious JS-serving website? Is this feasible/computationally worth it?
- lawrenceyan 7y agoThe fact that you can see these malicious scripts being served directly from a Baidu domain is a good reminder that effectively all major Chinese tech companies are totally at the whim of the Chinese government. It makes using any product / service from a Chinese based company basically never worth it just because of the security concerns.
- deleted 7y ago[deleted]
- Pvalencia2413 7y agoSilent is not a consent.
- ngcc_hk 7y ago“a web site Lihkg.com” is really an understatement as its title indicated. Given the “be water” and no leader, lihkg is really the only way to try to have some sort of info among possible noise (which popo is likely also post their confused Messages). There were discussion to cut off access by hksarg and a rush to install vpn is promoted. Guess they cannot firewall hk given its financial centre status. The evil empire and culture will try and try to harm liberty and human rights. If it is not so important you would not see many of hkers like me instead of posting in here and other places, but in concentration camp as northern Turks up north.
- clubm8 7y agoI can't read the OP because I'm using Tor, if anyone else is having similar issues wayback has it cached: https://web.archive.org/web/20191206074255/https://cybersecurity.att.com/blogs/labs-research/the-great-cannon-has-been-deployed-again https://web.archive.org/web/20191206074255/https://cybersecu... Too often I cannot browse anonymously because people abuse Tor to aggressively scrape things. Don't do that!
- vandal_at_your 7y agoFuck the idea of the browser as interpreter for untrusted code.
- classified 7y agoThe Chinese government attacks websites which support a free Hong Kong.