The Great Cannon has been deployed again
cybersecurity.att.com
cybersecurity.att.com
Connecting to a web page should not be consent to allow the operators of that web page to make my computer/phone do whatever they want on the net. It certainly should not be consent to delegate that power to others, either via a embedded link or a MITM attack.
Advocate the other direction: more freedom, including the freedom to say "thank you, browser, for being locked down by default, but I trust this website and I am okay with everything it wants to do".
Instead of locking the web down, let's give users the freedom to put on or remove as many locks as they want to live with. And letting make mistakes with that, too: you don't make things better by taking away important life lessons, either.
The problem doesn't have to be one of education if it is tackled as a legitimate UI/UX problem and served by a WC3 that supports the needs of end users over corporate partners.
I haven't noticed NoScript distinguish between http and https sources for javascript, but perhaps I don't visit sites that pull in javascript via http.
As for the DoS aspect, maybe it's time to do a CORS preflight on ALL cross-origin requests, including images. (Webfonts, for whatever reason, already require a CORS preflight. Probably because Adobe is on the W3C and they sell a service where certain origins can legally use certain fonts from their servers. I hate it when user security features get turned into subsidies for large corporations, but here we are.)
Of course, if you have broken TLS I guess you can just forge the CORS response.
Edit to add: I have read more comments and better understand the attack now. China is modifying the Javascript on Chinese websites that are being viewed from outside China. Making TLS mandatory would be a big help here. China could say "all Chinese companies must buy certificates from the Great Chinese CA" and they could still do the MITM. But with evidence of the CA issuing fake certificates to DoS websites, browsers would probably stop trusting that CA entirely. I imagine China would like to avoid that, so I feel like this would have stopped the attack.
"Hey Tim Apple/Microsoft/Google, if you want to do business in China you have to put our CA on your devices/software...".
At least Firefox would still be free from that. And Apple already has China-specific iOS, so they'd just activate the bad CA on Chinese devices...
But that is literally what web users want.
Everything you named is a fine opinion, but runs contrary to the wishes of the vast majority of millions and millions and millions and millions of web users.
EDIT: That said, browsers have features for users such as yourself to disable JavaScript, and there are third party extensions for finer-grained control. Again, adding these limitations is unpopular among web users.
No it absolutely does not.
Just because a user doesn't understand what Javascript is or how to diagnose why their computer is slow (is it an app, website, update, virus etc) does not imply consent.
Pretty sure that most people just want to be able to visit a website without it causing problems to their computer or to others.
And even if you do want to take silence for consent, the fact that the vast majority of millions of millions of web users do not install an extension to route around Google AMP indicates that they do not want the operators of the web page to do whatever they want, they want to run a restricted subset of what the web designer might imagine. AMP is extremely popular among web users; approximately 100% of Google users use it. (The more defensible argument, of course, is that users don't really want AMP, at which point the question of what users really do want gets back on the table.)
Also, users did vote with their feet against downloading EXEs from the internet - which can actually do whatever the developer wants - and using JS on the web platform, which can make unrestricted GET requests (even if it can't see the responses), sure, but can't do anything near "whatever." It stands to reason that users would gladly accept even more restrictions on the execution platform.
For the kinds of places that AMP is used, I would suspect so.
> Also, users did vote with their feet against downloading EXEs from the internet
So....this CAN happen???
> users would gladly accept even more restrictions on the execution platform.
The recent popularity of clipboard permissions, geolocation permissions, notification permissions, etc. would suggest otherwise.
What makes you so sure that web users care so much about the uptime of lihkg.com ?
What popularity? Do you have data that users tend to click "yes" on such permission prompts?
> What makes you so sure that web users care so much about the uptime of lihkg.com ?
I'm not sure I understand what you're asking or what you're responding to.
lihkg.com being down is the negative consequence of this code running, right?
You can see unintentional examples of this happening. Small sites get taken down occasionally when larger sites directly link to images or videos hosted there.
Come on now. Of course those devices can use TLS - they just can't do so in the capricious constraints imposed by the system of "certificate authorities". It's not a fundamental limitation of the technology.
If we were using something like noise protocol, nobody would be saying that tiny devices are incapable of proper security at the transport layer. There's just no clear way to assess the validity of a self-signed cert in the browser given today's political constraints.
The CA/Browser Forum allows certs up to 27 months - do routers sit on store shelves for 27 months before being configured? Do they even sit for 12 months? (Once they're online, they can renew their cert, possibly with the help of the vendor who can track the private key or something.)
Furthermore, this would require either not being able to change the IP for your device (bad) or sending information about the layout of your network to the vendor (I wouldn't trust them with that info).
Very few people care about this and the effort of maintaining a custom DNS and a CA certificate system (which, by the way, would need to be subjected to rigorous security testing) just isn't worth it.
Lastly, what's the point? Adding a little padlock isn't worth it if anyone can get a certificate for the router ip anyway. How do you ensure that the router connecting to your IP really has the mac address it claims? It only takes one person to get root on their router to invalidate the entire security system and given how somehow router vendors are still shipping command injection vulnerabilities, I wouldn't assume that they can prevent that as much as they'd like.
What I want is the option to give a router my own security certificate instead of the self signed one. Let me use my own CA or let me mess around with letsencrypt, split-horizon DNS and Selenium scripts if that's what I need. Consumers don't care about TLS on their router and this would be the cheapest option to solve it for prosumers.
Browsers and the people who sit on these committees are understandably more focused on their own use cases, but there really does need to be a viable certificate solution for small embedded devices, preferably works with mDNS too. I'm not going to hold my breath, but until this happens any/all IOT devices will remain largely insecure. Big co's (like my employer) can develop and deploy a custom solution, most companies cannot.
The immediate solution that occurs to me is installing a private CA, possibly one with name constraints for the vendor, because private CAs aren't held to the same rules about validity. I'm curious why this doesn't work - is it just that the tooling needed to make it happen isn't polished enough for small vendors?
I'm guessing that internet of things devices are, by their name, on the internet and can talk to a CA. Yes, this will require some way to give them a real domain name, but you could either give them names on the vendor's site or encourage people to get a domain name for themselves.
Vendor.com can then look at the opaque blob forwarded from their hardware and decide if they want to deligate trust to it.
(You cannot special-case "This server is untraceable", else a repressive government could blackhole that server and trigger the relaxed validation rules.)
How would you prevent this? What constitutes an "attack", and how would you make sure you're not interfering with non-malicious use cases?
For china need some way to handle that whole commerical-military-party all one entity.
I absolutely believe you, and wrote a document how to make improvement.
> Code from non-TLS pages should not be able to run at all.
Whether or not it is TLS is irrelevant. Either way the user may wish to put their own code, and either way the server operator can change things whether or not is what the user intends. (TLS does prevent spies from adding code, but not all unwanted code is from spies.)
> Instead of locking the web down, let's give users the freedom to put on or remove as many locks as they want to live with.
I agree. Furthermore, allow the user to override any behaviour they want to do, too.
Allow the user to examine and copy the script (possibly with modifications); if the script changes (whether due to MITM or due to the author altering it or due to some other company purchasing them), it no longer runs unless the user approves the new one, too. Extensions that only allow free software to run don't help either; just because it is free software does not necessarily mean it is a program the user wants their computer to execute. Or, maybe the user wants to execute a modified version instead!
An outbound browser firewall could helps also.
Hyperlinks generally don't open themselves. There is an obvious exception -- img tags[1] -- and I think it's worth considering whether they should be allowed to have the behavior they do. As far as I see, img tags load themselves so that, if you're editing HTML by hand, you don't have to deal with binary image data in the middle of what was supposed to be a clean text file. That may not be the right tradeoff.
[1] The img model got extended to other external resource loads, like script and css. But both of those frequently do appear as part of the same HTML that uses them. Image data can, but usually doesn't.
Also, external script loads are such an obvious problem that we got the Content-Security-Policy just to deal with it.
But to answer your question more directly, yes they clearly know what they are suggesting.
> These attacks would not be successful if the following resources were served over HTTPS instead of HTTP:
> http://push.zhanzhang.baidu.com/push.js; or
> http://js.passport.qihucdn.com/11.0.1.js
This seems overly generous. I personally would not assume that the government of China couldn't persuade Baidu or qihucdn.com to serve government-provided JavaScript.
It also assumes that the end users ("victims") here don't trust any Chinese certificate authority.
Highly unlikely, or else the suggestion would be to just ban http all-together. Http without the ability to load resources from other domains would break the majority of sites.
The evil empire and culture will try and try to harm liberty and human rights. If it is not so important you would not see many of hkers like me instead of posting in here and other places, but in concentration camp as northern Turks up north.
There is plenty of historical precedent for this: spammers' IP ranges would be blackholed to send a message to their ISPs that such behavior wasn't tolerated. That the Chinese authorities decide to play this game at the nation state level should not give them a free pass, but should result in a nation state level response.
I think we generally overestimate the hurt on the outside and underestimate the hurt on the inside considering the massive trade imbalance that China enjoys with the rest of the world.
Personally I have already pi-holed entire .cn and other domains.
UN sanctions are not imposed on bad state actors. They are imposed on weak state actors. UN sanctions have never been imposed on the US, China, Russia, Britain and France easily the worst state actors globally - the biggest weapons sellers and the cause of instability all over the world. They also are the 5 permanent security council members with veto power.
> I think we generally overestimate the hurt on the outside and underestimate the hurt on the inside considering the massive trade imbalance that China enjoys with the rest of the world.
China doesn't enjoy a trade imbalance with the "rest of the world". The enjoy it with the US primarily. They are net importers of Japan, South Korea, Saudi Arabia, Brazil, etc.
Germany, Japan, South Korea, etc also enjoy trade imbalance with the "rest of the world". Do you support sanctioning them?
> Personally I have already pi-holed entire .cn and other domains.
That doesn't do much if you really think about it. It's not like chinese individual, company or government are barred from owning everything from coms to orgs.
That is a great point and I agree with it.
However, the way I look at it, a state sponsored attack like this is no different from a country firing missiles or shells on another country from over the border. And as such, such attacks should not go unpunished and there need to be consequences. In addition, the countries being attached have a right and a moral duty to protect themselves.
The mechanisms of such I leave to those with the power to make it happen.
And yes, blocking .cn doesn't do much, but it does some.
We could potentially have sanctions that require Google to block commercial sites in China. That would definitely get their attention without massive financial implications on the economy.
This type of behavior CAN NOT be allowed to continue.
I’m sure this will garner plenty of whataboutism regarding how the west is imperfect (never minding that I didn’t say “the west”)...
There’s a limit to how much leverage any one side has on a sovereign countries policies (and how much they actually enforce them when they agree).
There’s also the question of the benefits of having China at all in these deals, some concessions and a growing dependence on western markets from initial deals is better than no deals.
Plus a wealthier China is good for the world and the billion people coming out of poverty, getting educated, and slowly becoming an advanced economy.
I’m not advocating for anyone controlling sovereign Chinese policies. They can continue their awful anti-humanitarian policies, fraud, IP theft, etc. I just don’t want my country aiding and abetting it. At very least I want my fellow citizens to be able to make informed purchasing decisions.
And I’m all for lifting people out of poverty, but I’d rather do it in a country with some minimum base line respect for human rights and integrity, and where my purchasing dollars don’t end up propping up some dictatorial system that bullies other countries.
The reality of China is that they need the global economy as much as the global economy needs them. No one entity can really pick up their ball and go home, as much as China would probably love to.
The first step could be sending CORS preflight, then requiring it, then just not allowing cross origin to different domains (but allow sub-/sibling- domains).
uBlock recently found an approach for blocking cnamed origins: https://github.com/gorhill/uBlock/commit/3a564c199260a857f3d...
Unfortunately (from my perspective) that'll do nothing to stop third party ad tracking but you can't have everything, I suppose.
Your defense idea might stop layer 7 attacks, but not lower level ones.
AT&T's writeup says the injection is only possible because it's HTTP (not HTTPS), and that there are two specific JavaScript files which sometimes serve up the malicious code.
So in case of known malware like this being served from within a geographic region... is there any way to filter this out at scale? Or is that computationally infeasible at scale, so it would have to be built into the browser or something?
The article also doesn't make clear -- is this DDoS coming exclusively from outside of China? Or is it injecting the same malicious code inside of China as well, and they're just not bothering to distinguish between requests coming from inside or outside the country? (In which case, the DDoS will continue regardless, just not with the rest of the world's help.)
Considering that the halting problem is undecidable, it's impossible to filter out the malicious scripts with complete certainty. The best you can do is use blacklists/heuristics which lead to an arms race.
>So in case of known malware like this being served from within a geographic region... is there any way to filter this out at scale? Or is that computationally infeasible at scale, so it would have to be built into the browser or something?
foreign ISPs can block port80 or http requests from coming into china. sure, it's going to break a lot of sites, but it's relatively simple for any site to get unblocked - all they need to do is set up letsencrypt.
This doesn't mean that you can't prove a big subset of scripts safe.
> The best you can do is use blacklists/heuristics which lead to an arms race.
You can also allow the scripts that automatically prove safe, plus other popular scripts you decide to explicitly allow, plus other scripts that are low-rate enough that you don't believe them to be a concern.
Any ISP could force unencrypted traffic through a deep packet inspection system that looked for this kind of malicious behavior. That would be widely seen as a betrayal of the "big dumb pipe" expectation.
The computation itself is not infeasible at scale. But any ISP attempting this would see swift and brutal political pushback and almost certainly lose customers over it.
Do they just not care?
Some day soon a war will not be started with an assassins bullet but with a tool like this. I wonder when we start looking at them the same way?
The audience is other Asian and African states. The message is "we can act with impunity". The US will probably do some tit-for-tat exchange, but the US scope to do anything is limited due to the potential for impact on US businesses.
They're also directing lasers at helicopter pilots, which is much closer to a actual war than mere bits.
https://www.abc.net.au/news/2019-12-06/chinese-fishing-vesse...
The cannon doesn't have to work all the time, just once effectively, and possibly even accidentally.
After the meeting, Franz wanted to travel to the hospital to visit the civilians who'd been wounded by the errant grenade. En route, his driver, confused, took the same route from the morning procession. When they realized what was happening, they told him to turn around and get the out if there. When the driver stopped to turn around, they were ~1 block from the site of the first assassination attempt. One if the co-conspirators (who had lost his nerve the first time, and had been milling around and hoping that Franz would come back by), was standing where the car came to a stop. Two shots killed Fran's Ferdinand and his wife.
Fun fact about this--Franz Ferdinand's death was not the cause of the Great War in the way that people tend to think it was. The assassination caused the war in the sense that it was a convenient excuse for a war that the Austro-Hungarians already wanted, but not because (Austro-Hungarian Emperor) Franz Joseph wanted revenge or anything like that. In fact, Franz Joseph's secretary later said that he "almost seemed grateful" that Ferdinand (whose marriage was so problematic that he had been forced to proactively abdicate on behalf of his children) was out of the way.
0 - Peace 1 - Trade War 2 - Financial War 3 - Electronic War 4 - Shooting War
Note that 1 & 2 are different types of Economic war, and could be grouped together. The steps occur in order, but steps can be skipped.
From a US-centric point of view, North Korea and Iran seem to be at #3. China & Russia are at a limited version of #2.
Chinese/HK seem to be at #3 with each other.Given how invisible Electronic War can be, it's possible that they are deep in #3. It's also possible that #4 might be initially fought with HK Police forces as a proxy. Think of that as "4a".
"Countries that trade with each other don't make war with each other."
As we isolate countries and disrupt trade we definitely are increasing the risk of conflict.
I'm pretty sure this was the prevailing thinking prior to World War 1. A large scale conflict would be so damaging on a human and economic level that most assumed the people in power would find away to stop a massive war from breaking out. Well, they were right about the first assumption, but very wrong about the second.
There's plenty of good things from a moral perspective about power being diffused away from a hyperpower hegemon, but stability and peace have never been among the side effects.
Nobody really cares, except for those directly involved. Sad but true, nobody will ever go to war for that, for foreign citizens.
> I want my cheap plastic consumer devices!!
People do actually want that. And their cheap shoes and clothes and...
Foxconn's suicide rate is lower than China's, along with all 50 US states. They just employ a gargantuan amount of people (400k). I don't know much about the working conditions there, so I don't have a position, but it doesn't look like there's evidence to suggest that the working conditions have anything to do with the fact that some of their employees committed suicide.
To put it another way, there's roughly as much evidence of this as there is that working in a factory in Nigeria causes sickle cell anemia.
Page 25 (but see also page 23) https://assets.publishing.service.gov.uk/government/uploads/...
Fencing off tall buildings is a useful short-term suicide prevention measure.
It's impossible to prove causality, but Europe has never seen longer and more widespread peace than the last 70 years.
Tons of CPP members are getting rich off the economy which includes a lot of trade and foreign debt.
There’s plenty of correlation here.
Here's what Otto Mallery said though:
"If soldiers are not to cross international boundaries, goods must do so. Unless the Shackles can be dropped from trade, bombs will be dropped from the sky."
This was a common argument as to why WWI couldn't happen, countries were far too economically dependent, everyone would be ruined.
Except it did happen, and everyone was ruined.
At worst, it was an affirmation repeated, as with most affirmations, in the hopes that the repetition would make it true, which it doesn't, and for the usual reason, that it generally wasn't.
https://www.theatlantic.com/magazine/archive/2001/04/hitlers...
https://www.phactual.com/8-american-companies-that-worked-wi...
https://www.toptenz.net/top-10-american-companies-that-aided...
How many major wars in the last 100 years were preceded by trade wars or electronic wars (I don't know what a financial war is, trade embargoes? - embargoes are not trade wars)? Perhaps my view is a bit us-centric (there have been many small wars in africa that I don't know the history of), but I don't think that us conflict participation in Iraq, Yemen, Libya, Grenada, Vietnam, Korea, WWII, or WWI were preceded by those sorts of policies. To find a trade war that preceded a war I think you might have to go to the US fighting in central america (banana wars), or maybe the civil war.
Meanwhile the US has engaged in trade wars with plenty of countries it hasn't fought with, dominantly europe (via the banana trade wars, not to be confused with banana wars, e.g.), and Japan.
https://www.amazon.com/New-Confessions-Economic-Hit-Man/dp/1...
"Peace" is built from war's stalemates. As the most violent (and therefore effective) means become ineffective, combatants shift towards less effective means, to the point that the war (which is still ongoing) continues through diplomacy and trade.
Hence, "war is diplomacy by other means."
Diplomacy and trade are means of gaining an advantage in the underlying (now "cold") warfare. They're maneuvers to defeat the existing stalemate. If either side is able to obtain an economic (or other advantage) sufficient to defeat their opponent in a more violent form of warfare, then they will return to violence because that is the basal state of nature.
The worst thing you could ever have in trade / diplomacy is a good working relationship that isn't balanced and equal. A trade failure is itself a stalemate which can strengthen peace, so long as it occurs before too great of an advantage is gained any group.
As the grandparent said - steps can be skipped. Since 3 is a relatively new medium for offensive actions, I suspect there are not a lot of well-known examples around. Would be interesting to see if any currently active conflicts were preceded by DoS (not necessarily Distributed, could be just a "cable cut" from outside), and how long before it escalated to active conflict.
The whole point of the cannon is that you can leverage the bandwidth of other countries. The CCP already controls the telecoms in China. They don't need to hijack Chinese computers for DDoS attacks when they can directly DDoS from their ISP's backbone.
and in case I'm totally wrong, what mitigations are feasible? More trade war such as by compelling ISP's to null-route Chinese businesses like Baidu.com as a form of sanction?
When I signed up, they emailed me to welcome me to the site (they actually require manual authorization of users by an admin, which is... refreshing, but uncommon). The email ended by stating that if I lost my password, they could "recover it" and send it back to me.
I raised a thread about it in one of their off-topic sections, and got harassed - "How secure do you need your browsing to be?" (And hey, I mean, I was asking them to do more work)
But it stands out that most of the public doesn't know, and doesn't care to know. Even a site that's populated by people with net worths and/or incomes that average in the six-to-seven figure range, that they probably signed up for with the same email address and password that they use for their bank and brokerage accounts.
HTTP should come with a warning. Furthermore, it would be fan-fucking-tastic if there was some generalizable way to (automatically) audit a website's security practice. Like, a crawler that just runs standard OWASP-style attack-vector checks, and sends an email to the site's owners when one succeeds. And then put that data into a database and warn users (with a browser plugin) when they are creating credentials for sites with bad security.
Next day, I can't login. I use the "forgot password" link. They send me and email, and it has my password in it! Bad, right?
That isn't all. My password, they said, was "password1". They silently stripped out the special character.
I just about flipped a table at how security-shallow people who build websites can be.
If it seemed like they were doing a hash then compare, I would wonder if they are using the legacy unix crypt that truncates passwords at 8 characters.
And if they did strip it out, that is bad. That's the point.
e.g. Don't assume the email address is owned by the person making the claim. You can sign up for an account with an email and if it's not verified or the verification is mis-clicked or phished into being clicked the original account owner would never know the difference.
Still, at least with OpenID Connect you know your password isn't sitting in plain text.
Perhaps explain to them that many people (unwisely) reuse passwords for many sites... possibly including their banking.
We're talking about China, so that's probably not going to work: Chinese users are using Chinese browsers [1] to access Chinese websites. I don't think Chinese browser-makers and website operators are going to take action against their government like that.
[1] https://www.fastcompany.com/3058432/the-top-3-web-browsers-i...
It would mitigate attacks from inside China against outside entities, which for somebody not based in China is all I want.
> [Nicholas] Weaver said the attacks from the Great Cannon don’t succeed when people are browsing Chinese sites with a Web address that begins with "https://", meaning that regular Internet users can limit their exposure to these attacks by insisting that all Internet communications are routed over "https" versus unencrypted "http://" connections in their browsers. A number of third-party browser plug-ins — such as https-everywhere — can help people accomplish this goal.
> But Bill Marczak, a research fellow with Citizen Lab, said relying on an always-on encryption strategy is not a foolproof counter to this attack, because plug-ins like https-everywhere will still serve regular unencrypted content when Web sites refuse to or don’t offer the same content over an encrypted connection. What’s more, many Web sites draw content from a variety of sources online, meaning that the Great Cannon attack could succeed merely by drawing on resources provided by online ad networks that serve ads on a variety of Web sites from a dizzying array of sources.
[1] https://krebsonsecurity.com/2015/04/dont-be-fodder-for-china...
[1] https://news.ycombinator.com/item?id=21726617
> and in case I'm totally wrong, what mitigations are feasible? More trade war such as by compelling ISP's to null-route Chinese businesses like Baidu.com as a form of sanction?
Probably something like this, but I'm afraid of where that would lead.
Then they can view the traffic even going to and from foreign sites who would not comply with an order to share private keys and no safe browsing blacklist (like that would be accessible from inside the regime anyway) will help you.
Addressed here: https://news.ycombinator.com/item?id=21721843
>Shit, they can require vendors include a hardware backdoor, especially since so much of that hardware is produced domestically.
If they're only doing it for local computers, the consequences/response is the same as the previous paragraph.
If they're doing it for foreign computers on a mass scale required for a DDoS attack, if discovered will torpedo their entire electronics sector. All the "ban huawei" politicians will have a field day with that.
If I'm understanding other comments correctly, browser vendors installing HTTPSEverywhere cuts down the potential for this Great Cannon attack from 7.7 billion users to 1.4 billion. An 80% reduction seems significant.
> In cryptography, forward secrecy (FS), also known as perfect forward secrecy (PFS), is a feature of specific key agreement protocols that gives assurances that session keys will not be compromised even if the private key of the server is compromised.[1] Forward secrecy protects past sessions against future compromises of secret keys.[2][3][3]
* https://en.wikipedia.org/wiki/Forward_secrecy
There's still the risk of MITM identity spoofing of course.
Ultimately, if an attacker has all your keys and controls all your traffic, there's nothing left that distinguishes the attacker from you. No security is possible in that scenario.
"Mitigations
These attacks would not be successful if the following resources were served over HTTPS instead of HTTP:
http://push.zhanzhang.baidu.com/push.js; orhttp://js.passport.qihucdn.com/11.0.1.js
You may want to consider blocking these URLs when not sent over HTTPS."
https://developer.mozilla.org/en-US/docs/Web/Security/Same-o...
sudo echo -e "\n\n# Null route the Great Cannon:\n0.0.0.0 baidu.com\n0.0.0.0 qihucdn.com\n" | tee /etc/hosts
... but I know I'm only fooling myself.thanks (I admit didn't test it because I use `python3 ./updateHostsFile.py` to take care of /etc/hosts)
A slightly less broad measure that's just as effective would be to block unencrypted http traffic from entering China. Want to get unblocked? Get letsencrypt.
A even better (but slightly greyhat) route would be to inject HSTS headers with the maximum expiry date. This will cause any visitor's browsers to get "infected" with an unskippable warning, forcing them to upgrade no matter what.
Browsers are already moving to explicitly label HTTP sites as "not secure"
> operates by injecting malicious Javascript into pages served from behind the Great Firewall. These scripts, potentially served to millions of users across the internet, hijack the users’ connections to make multiple requests against the targeted site. These requests consume all the resources of the targeted site, making it unavailable:
This is important for public discourse at least, because if it's technically undeniable that Chinese authorities are behind this attack then you can immediately assume than anybody saying that China has nothing to do with it is either acting in bad faith or is largely uninformed.
As we've seen multiple times in the past the existence or non-existence of conclusive proof is largely irrelevant when it comes to international policy anyway so the opinion of US courts is frankly besides the point.
And even then, it could be some third party cache poisoning attack, etc. The citizenlab evidence would look exactly the same.
This is likely China, as I said, but let's not pretend that we know more than we do.
Then there's the question of how separate the operating company is from the Party..
That's not an accurate summary of what they're doing.
They're intermittently serving poisoned js in place of known analytics scripts.
Which changes the potential "who" a bit.
There’s a high probability this is state run. There’s probably tons of offensive cyber teams in China and these are hitting sites like Greatfire.org which documents Chinese censorship (which was also why Github was hit if I’m not mistaken).
It’s not surprising that the organs of censorship would be used to target attempts to expose said censorship.
AFAIK, those people are generally not capable of performing a MITM attack on traffic coming from sources inside China.
baidu and Qihoo 360 are massive companies. Serving the stuff either means they are doing it deliberately (on behalf of the government), or an active MITM is doing it, which given the scale can only mean ISP and ergo (since this is China) government level. The active MITM seems plausible since a) only unencrypted http traffic gets injected (so far), and b) the Chinese government wouldn't want to put the onus on two of their most important internet companies alone.
I use Firefox's built Enhanced Tracking Prevention, that some sites call "ad blocking" but in reality it is super easy to have ads that don't get blocked by it, just make them non-creepy.
1. Online ads today are so bad they must be blocked
2. But blocking ads blocks revenue for sites we like
3. So we should pay for them more directly
4. But I'm not about to set up 100 different monthly subscriptions. These corporations are not trustworthy and I cannot monitor this many bills.
5. We need a solution to simplify money -> content -> creator transfer
6. There's been many attempts at that, but there's too many players who want the power and control that comes with wedging themselves in between consumers and creators.
7. So we're stuck.
There's no ethical reason for us to "pay" these scummy actors, including Google, Facebook, Reddit and Twitter, after they destroyed all viable alternatives by giving away their products free and THEN add advertising.
As you intimate, there's also nothing intrinsically necessary to the advertising model for it to be served by different domains, with 3rd party cookies and third party javascript. Nor is it necessary to have auto-play videos, popups, etc. Even someone fairly benign like the Guardian is now infested with up-sells and adverts if you look at it without an adblocker.
So the sites brought it on themselves.
You want to support their ads, go ahead, but don't ask us to come up with the alternative model. You have no moral high ground to preach to us from, all these sites used a bait and switch to get on top. Right now if I look at facebook every 2 or 3 stories are adverts, where 5 years ago it was far less, and for google a huge chunk of the top of the results page, up to three results worth, are adverts.
None of these are clearly marked imo, nor are they necessary, they're making billions in profit. They can do it because they monopolized the market.
It's not a question they need to answer, that's the problem of the companies that caused this mess.
> Yet they still expect these websites to exist.
Not really, they just use what exists, not what they expect to exist.
This folk has an answer: display ads the ol' fashioned way, with a pair of <a> and <img> tags.
I for one certainly don't have that expectation. I understand sites have non-zero operating costs, and/or staffing and other expenses in order to create and serve interesting content.
If someone rolls out (without using the word blockchain or any derivative) a way of doing the web equivalent of .99 per track, no middlemen/Elsevier types, just 'pay the originating site for full permanent access to this page', I'll do that in a heartbeat.
I buy paper books and sit and enjoy them thoroughly... web content transparently priced with reasonable, honest rates get at least close to that style.
https://stallman.org/articles/internet-sharing-license.en.ht...
Phil Hunt (Pirate Party UK): A Broadband Tax for the UK (2009)
https://cabalamat.wordpress.com/2009/01/27/a-broadband-tax-f...
Myself: Universal Payment Syndication (2014)
https://old.reddit.com/r/dredmorbius/comments/1uotb3/a_modes...
Joseph Stiglitz: "Knowledge as a Global Public Good"
http://s1.downloadmienphi.net/file/downloadfile6/151/1384343... (PDF) (pp 308-325)
If users don’t need an account to get the content and they still get ads with the paid account, what exactly are you offering in exchange for the payment?
You do have something of value: Bandwidth.
Injecting ads/affiliate or whatever js in webpages, stealing social media tokens to do follower boosting business and selling optic fiber traffic dump is also common for Chinese ISPs.
https://web.archive.org/web/20191206074255/https://cybersecu...
Too often I cannot browse anonymously because people abuse Tor to aggressively scrape things. Don't do that!
Let China enjoy it's solitude and we'll enjoy our openness.
Cut them off completely, and we will never find out about all the human rights violations taking place in their country, and their government will be able to brainwash its citizens even more easily.
Today we're just finding about them, not able to do anything, so that won't be much different from the status quo but the benefits would be immense.
If I get the attack scenario right, valid user IPs from behind the great firewall are driving traffic to the webservers, and so what are some examples of anti-DDoS mitigations that are effective in filtering out the adversarial traffic?
Edit: better/cleaner version: https://outline.com/8BBX3b
Does anyone else have a sense of what (if any) pragmatic technical steps could effectively deter or neuter this tactic?
If the network can't demonstrate the ability to at least pump the brakes on this, it's hard to imagine other states or even the owners of large safe-monopoly ISPs won't get a little jealous of the tool.
1. non-chinese user visits a chinese site
2. the traffic goes through the gfw, which inserts malicious javascript
3. the user executes the malicious javascript and starts ddosing the victim site
Blocking chinese users won't help, since non-chinese visitors will still ddos your site.
I was especially impressed with their getting the target to retrieve, resize and transmit an image: that's a smart way to waste time...
Can someone explain how using HTTPS would mitigate this attack?
It makes using any product / service from a Chinese based company basically never worth it just because of the security concerns.
I suspect that a lot of businesses would flex muscle on both sides to get that to stop really quickly.
It would be a hard policy to implement on our side, but likely very effective. Its almost like we need someone in power smart enough to ASK telco's and carriers to DO such a thing.
Is this feasible/computationally worth it?
Are the vendors just cowards?
$ nslookup -type=soa lihkg.com
Server: 8.8.8.8
Address: 8.8.8.8#53
Non-authoritative answer:
lihkg.com
origin = kevin.ns.cloudflare.com
mail addr = dns.cloudflare.com
serial = 2032679273
refresh = 10000
retry = 2400
expire = 604800
minimum = 3600
Authoritative answers can be found from:China has better tools, like XORDDoS.
The attack uses network-level injection to add malware to HTTP requests for resources served from inside China. This malware then runs on hosts anywhere in the world and effectively DDoSes the targets. It is true that if these specific requests were made over HTTPS rather than HTTP, this particular attack would be mitigated.
Unfortunately the point that is being missed here is that if these resources had been served over HTTPS, this attack simply would have been implemented in a slightly different way. The suggested mitigations would work post-facto. However, if had they been in place prior to this attack, which is the alternative we have to consider, other means would have rendered them useless.
The fact is that any website hosted in China is directly accessible to the CCP for hosting these attack payloads. There is an ICP registration system and a chain of access to hosting environments that grants full network control and full access to any server to the authorities at any time they choose. Servers that are not part of this system are simply not allowed to host websites on the Chinese internet. Further, there is direct political control over every major internet company.
This is such a fundamentally different situation that it can be hard for American observers to understand what range of potential responses are meaningful.
The reality is that any network request that is served from China is fully within the political power of the CCP to alter. Whether this involves HTTP or HTTPS or whether implemented via the GFW or by direct changes to endpoints within internet companies is immaterial. Beyond the logistical costs of these actions within China, nothing of any consequence is changed by such minor technical mitigations.
What these attacks show is not just the capability but the willingness to use that capability in an offensive capacity against political targets.
The difference between the internet of independent sites in the US and the situation of near-total political control over resources on the network in China can hardly be overstated. This is why technical solutions that seem completely reasonable from an American perspective are pointless in reality. The threat model of the world's largest online population with all network resources under direct political control is simply too unfamiliar. If the political will exists to use those resources offensively, technical countermeasures will always be ineffective, unless they are so seemingly disproportionate that they become essentially political acts, like depeering.
Meaningful responses are those that affect the political willingness of the CCP to weaponize the internet. Weaponization will destroy the internet as we know it, and raising awareness before this kind of thing becomes routine may be the last chance we have to avoid it.
This is a political problem, and does not have a technical solution.