> operates by injecting malicious Javascript into pages served from behind the Great Firewall. These scripts, potentially served to millions of users across the internet, hijack the users’ connections to make multiple requests against the targeted site. These requests consume all the resources of the targeted site, making it unavailable:
HTTPS has real costs, but if you're distributing javascript at high volumes you should pay them.
(Handling the ddos is harder when the target is https though... Can't know what the handshake is about until you've spent the cpu on handshaking)
This is important for public discourse at least, because if it's technically undeniable that Chinese authorities are behind this attack then you can immediately assume than anybody saying that China has nothing to do with it is either acting in bad faith or is largely uninformed.
As we've seen multiple times in the past the existence or non-existence of conclusive proof is largely irrelevant when it comes to international policy anyway so the opinion of US courts is frankly besides the point.
Then there's the question of how separate the operating company is from the Party..
baidu and Qihoo 360 are massive companies. Serving the stuff either means they are doing it deliberately (on behalf of the government), or an active MITM is doing it, which given the scale can only mean ISP and ergo (since this is China) government level. The active MITM seems plausible since a) only unencrypted http traffic gets injected (so far), and b) the Chinese government wouldn't want to put the onus on two of their most important internet companies alone.
And even then, it could be some third party cache poisoning attack, etc. The citizenlab evidence would look exactly the same.
This is likely China, as I said, but let's not pretend that we know more than we do.
That's not an accurate summary of what they're doing.
They're intermittently serving poisoned js in place of known analytics scripts.
Which changes the potential "who" a bit.
There’s a high probability this is state run. There’s probably tons of offensive cyber teams in China and these are hitting sites like Greatfire.org which documents Chinese censorship (which was also why Github was hit if I’m not mistaken).
It’s not surprising that the organs of censorship would be used to target attempts to expose said censorship.
I haven't looked at this closely enough to know how the script's chaining works, or if China retains MitM capability across TLS.
Regardless, it's nice to be reasonably accurate when we're tossing around claims.
AFAIK, those people are generally not capable of performing a MITM attack on traffic coming from sources inside China.