4 ms·
It is and it isn't powerful. I was pretty impressed by how they attacked GitHub (not why) and in doing so they showed the power of the tool. However, the reque
by borgia 11y ago
It is and it isn't powerful. I was pretty impressed by how they attacked GitHub (not why) and in doing so they showed the power of the tool.
However, the requests it made could have easily been turned back against Chinese business if Github so wanted. It couldn't be done because there was no reasonable who to turn the traffic back against. If non-Chinese companies simply said "If China uses these tools we will redirect the traffic at a number of large Chinese businesses" then a lot of the power in the tool is immediately withdrawn.
At least that's my interpretation of it.
- fweespeech 11y agoYeah, if GitHub had used a 301 Moved Permanently to some Chinese website I think it would have been interesting [rather than responding with the alert message]....however that probably would be deemed "attacking" someone.
- Fuxy 11y agoNot really it's technically deflecting the attack back at your opponent just like martial arts. I would more likely call it active defense. :) Note: Journalists whil always go for the sensational that's no reason not to do it.
- fweespeech 11y agoDo you honestly believe that is how the average journalist would report it and the general population would perceive it? 'cause I immediately see headlines like: "Github hacks China over censorship!"
- samiam1 11y agoIt would've been interesting if they had made the 301 point back to Baidu.
- Sanddancer 11y agoWhile fun, it almost certainly would have resulted in China moving to the Syn flood stage faster. That being said, I'm always a fan of the classics, and would have probably gone for a redirect to goatse or the like. Given that the script was giving github full control of the page, a bit of shock and awe would have been rather fun.
- ddlatham 11y agoThe reason it is powerful is not this particular attack. It's a demonstration that they are willing and able to inject malicious responses to any request going to a Chinese resource (web site, analytics service, ads, etc.). Imagine if instead of returning some DoS javascript they deliver a payload to silently exploit a vulnerability in your browser/OS (and they are surely capable of finding or purchasing those) to do whatever they want with it: - Add it to a botnet - Steal your personal data - Infiltrate your corporate network - Wipe your system (punishment for those accessing or producing GFW circumvention software) Are you confident your browser never makes HTTP requests to Chinese servers? Are there tools we can install to prevent it? [EDIT: It looks like two separate HN stories got merged, and the comments along with them. Didn't know that could happen, but this comment now appears twice here.]
- TuxMulder 11y agoForgive my ignorance, if anyone knows of an initiative that does what I am about to suggest... It's an idea off the top of my head, without too much thought: Is it about time we start to sign our javascript so that browsers will only execute the JS if it can verify the signature? I know, there are so many drawbacks, especially for those of us who are developers, but I'd value security on the Internet over the additional development overheads. Or depreciate HTTP and enforce HTTPS only?
- shabble 11y agoIt crops up occasionally, the issue has always been the effort of client support, and that it only anchors the validity to that of the document referencing the javascript (or whatever). These days there's an active spec underway for "Subresource Integrity" at w3: http://www.w3.org/TR/SRI/ http://www.w3.org/TR/SRI/, which is pretty much exactly that, so hopefully it'll happen eventually.
- TuxMulder 11y agoThanks for the link :)