4 ms·
I’m also confused because based on that screenshot, the page has HTTPS, which would mean either the block would be client-side, or the entire domain is blocked.
by quink 2y ago
I’m also confused because based on that screenshot, the page has HTTPS, which would mean either the block would be client-side, or the entire domain is blocked.
- josephcsible 2y agoOr that China uses rogue root CA's to MITM their citizens' HTTPS traffic.
- jonny_eh 2y agoOr they scrape sites and block domains that have pages that contain keywords.
- tgv 2y agoWikipedia says "The National Intelligence Law of the People's Republic of China theoretically allows the Chinese government to request and use the root certificate from any Chinese certificate authority,[60] such as CNNIC, to make MITM attacks with valid certificates." [https://en.wikipedia.org/wiki/Great_Firewall#Active_filtering https://en.wikipedia.org/wiki/Great_Firewall#Active_filterin...]
- gruez 2y agoKeyword is "theoretically". Thanks to certificate transparency, such misissuances would be detected relatively quickly, eg. https://news.ycombinator.com/item?id=42284202 https://news.ycombinator.com/item?id=42284202. To my knowledge it hasn't actually happened in practice.
- rwmj 2y agoOr has a backdoor in all China-built hardware.
- TJSomething 2y agoOr maybe it's just an selectively enforced ban using on software that doesn't accept their root certificates.
- quitit 2y agoThis is the real question. One that I would love to know the answer to. If it's a Chinese run spider that flags websites that contain banned terms, does this mean that we can effectively block certain websites from China as a form of denial attack? There are many sites which allow user submissions without a strong administrative overview. E.g. Could Booking.com be blocked to the Chinese audience by a listing including certain keywords on their page or in imagery.
- gruez 2y ago>If it's a Chinese run spider that flags websites that contain banned terms, does this mean that we can effectively block certain websites from China as a form of denial attack? Yes? That's basically why a bunch of western social media sites are banned in china, because people post subversive content there and the site's administration refuses the government's request to take it down. If you tried it on booking.com or whatever, it won't work, both because your comments will be taken down by site administration for being off topic, but also because the site is big enough that they won't take automated actions (hopefully). At best you can take down small to medium sites that don't have active moderation teams. Moreover, this isn't an attack that's limited to china, it can be used against any sort of content blocking system. Sites have been blocked from google browsers (via google safe browsing) due to malicious UGC, and you can even take down the whole site if you email the abuse department of their hosting provider.
- pastage 2y agoI have deep experience with black listing on the net, and nothing compares to the Chinese censor machine. A comparison with mundane things like malware is dishonest. You should not attribute the great firewall to anything else than the malice it is.
- gruez 2y ago>I have deep experience with black listing on the net, and nothing compares to the Chinese censor machine. A comparison with mundane things like malware is dishonest The comparison was with how both the chinese censorship system and other blocking systems can be susceptible to the same attack (ie. people posting UGC to get a site banned). At no point did I imply that they were comparable in any other way.
- deleted 2y ago[deleted]
- libeclipse 2y agoChinese censors use active probing to scrape hosts and block anything with problematic content or services. It's not just DPI based.
- chongli 2y agoNo need to bypass HTTPS. Just crawl any server that shows up in the logs and block the domain if it has any blacklisted keywords.