3 ms·
> For a text-only blog If somebody MITMs it, they can serve you anything they want.
by robonerd 4y ago
> For a text-only blog
If somebody MITMs it, they can serve you anything they want.
- enriquto 4y ago> they can serve you anything they want. Great. More books! No really, I don't understand this argument. A static site served by plain http is perfectly appropriate. It's like a poster hanging on the wall for all to see. Of course people can paint over it, but it doesn't really matter.
- robonerd 4y agoThey could serve you javascript that exploits your browser. At the very least, they could replace that bitcoin donation address with their own. That's a tempting target if nothing else.
- SquareWheel 4y agoAnd "they" isn't just your ISP. It's also that free wifi hotspot you connected to, or the hotel service, or your company's network. Even if you trust your ISP (and you probably shouldn't), there are other bad actors to be aware of.
- Aachen 4y agoIf you think you're high value enough to have someone target you specifically by getting on your LAN or gaining access to (or coercing) an upstream ISP to serve you a browser 0-day reachable only by laying in wait for you to visit an HTTP site because there is no other way in, that's not going to be for a free books website.
- robonerd 4y agoConsider that the downloads page for this site tells you to use their tor hidden service. If you open http://pilimi.org/ http://pilimi.org/ in Tor, you'll go through an exit node that could be MITMing everybody opportunistically, not targeting you specifically.
- Tepix 4y agoThis is a site asking you to commit piracy, i can totally see the some agency intercept it and replace the onion addresses with theirs so they can track everyone down.
- Aachen 4y agoIf enough people find it okay to take such extreme measures for mundane, nearly victimless crimes, I hate to think what the future will be like. In the past, hoarding exploits was considered something for the military, for national security, and even there it was a hot debate and controversial and many parties/countries wanted restrictions like time limits until it's reported to the vendor. Entering homes was a thing of warrants because we wanted to limit government overreach. Now it's okay to employ both of these for reading books without permission? If there's one of you then there's probably more. The future is bright.
- Tepix 4y agoA Man-in-the-middle attack against a HTTP website to de-anonymize people would not require a 0-day exploit. I agree that it would be an extreme measure.
- solarengineer 4y agoI can confirm this. A friend uses a government backed ISP, and he frequently receives popups announcing local government announcements.
- criddell 4y agoHTTP connections can be used as a weapon against others. One example is China’s Great Cannon. https://citizenlab.ca/2015/04/chinas-great-cannon/ https://citizenlab.ca/2015/04/chinas-great-cannon/
- Aachen 4y agoThat's quite dated by now. If you are in a position to inject traffic, you are likely also able to simply use that uplink to send traffic of your own. I'd be surprised if this is still in use, especially outside of China (or a poor not-so-tech-savvy country like North Korea) and wasn't just a quick hack at the time.
- criddell 4y agoIt's only dated if the vulnerability has been patched. In this case, the only way to patch it is to serve over HTTPS. If it was a quick hack, then that makes it even worse. Difficulty is a mitigating factor.