4 ms·
> NITEC is responsible for maintaining a list of sites which they want to be made unavailable to Danish citizens. Each day the country’s Internet service provid
by feralchimp 15y ago
> NITEC is responsible for maintaining a list of sites which they want to be made unavailable to Danish citizens. Each day the country’s Internet service providers retrieve the list and then apply DNS blockades across their infrastructure.
So that's already pretty weak, but then we find out it's implemented with a shared Windows folder.
sigh.
- fabricode 15y agoIn order to prevent this kind of censorship in the future, a motivated individual just has to drop the ip address / hostname of the computer sharing the folder into the folder itself. Problem solved.
- sp332 15y agoThe article says "retrieved" from a "folder". It doesn't even say whether it was Windows, or on a server somewhere. It could have been FTP or something.
- pdeuchler 15y ago"It could have been FTP or something" And that makes it better?!
- fraserharris 15y agoFTP is still the standard for file transfer in most large corporations. It is as secure as other methods.
- sp332 15y agoFTP has no security at all. Usernames, passwords, and data are all sent in the clear, in plain text. https://en.wikipedia.org/wiki/Ftp#Security https://en.wikipedia.org/wiki/Ftp#Security
- drivebyacct2 15y ago>FTP is still the standard for file transfer in most large corporations. Um, what large corporations? And on God's green earth, why? >It is as secure as other methods. No, no it absolutely isn't. In terms of highly available ways of sharing data, FTP is the least secure of all of them. And it's not even a close race.
- nkassis 15y agoYou might be thinking of SFTP which is a very different thing. FTP itself is very insecure and should only ever be used for anonymous downloading.
- deleted 15y ago[deleted]
- freehunter 15y agoWait until you find out how your OS gets updates, or your browser gets updates, or your certificate revocation list gets updated.
- palish 15y agoHow?
- freehunter 15y agoThe software retrieves the data and applies it from a list maintained by the software distributor. This sounds, from the high-level overview they gave, exactly the same as all update servers.
- colonelxc 15y agoTo be fair, for Windows and many Linux distrubutions (don't know about OS X) have signed packages, so it's not like they're grabbing any data and blindly running it.
- pjscott 15y agoAnd they also have some site which blocked pages redirect to, with dire warnings about child pornography. With this infrastructure in place, and a little bit of cleverness, you could Rickroll an entire country. Or redirect everything to the Goatse guy, or a phishing page, or something even worse.