and in case I'm totally wrong, what mitigations are feasible? More trade war such as by compelling ISP's to null-route Chinese businesses like Baidu.com as a form of sanction?
and in case I'm totally wrong, what mitigations are feasible? More trade war such as by compelling ISP's to null-route Chinese businesses like Baidu.com as a form of sanction?
When I signed up, they emailed me to welcome me to the site (they actually require manual authorization of users by an admin, which is... refreshing, but uncommon). The email ended by stating that if I lost my password, they could "recover it" and send it back to me.
I raised a thread about it in one of their off-topic sections, and got harassed - "How secure do you need your browsing to be?" (And hey, I mean, I was asking them to do more work)
But it stands out that most of the public doesn't know, and doesn't care to know. Even a site that's populated by people with net worths and/or incomes that average in the six-to-seven figure range, that they probably signed up for with the same email address and password that they use for their bank and brokerage accounts.
HTTP should come with a warning. Furthermore, it would be fan-fucking-tastic if there was some generalizable way to (automatically) audit a website's security practice. Like, a crawler that just runs standard OWASP-style attack-vector checks, and sends an email to the site's owners when one succeeds. And then put that data into a database and warn users (with a browser plugin) when they are creating credentials for sites with bad security.
e.g. Don't assume the email address is owned by the person making the claim. You can sign up for an account with an email and if it's not verified or the verification is mis-clicked or phished into being clicked the original account owner would never know the difference.
Still, at least with OpenID Connect you know your password isn't sitting in plain text.
This "dilution is the solution to pollution" argument is the excuse the FAA uses for forcing everyone to use leaded avgas. This should be more of a scandal. The FAA is basically helping maintain a harmful oil company monopoly at the expense of the world.
This is not just about recreational aircraft. For example, 45% of the Canadian commercial fleet is piston engine based. Incidentally, Canada was involved in a test program with the FAA for leaded fuel replacements. The FAA recently dropped out of that program.
Next day, I can't login. I use the "forgot password" link. They send me and email, and it has my password in it! Bad, right?
That isn't all. My password, they said, was "password1". They silently stripped out the special character.
I just about flipped a table at how security-shallow people who build websites can be.
If it seemed like they were doing a hash then compare, I would wonder if they are using the legacy unix crypt that truncates passwords at 8 characters.
And if they did strip it out, that is bad. That's the point.
Perhaps explain to them that many people (unwisely) reuse passwords for many sites... possibly including their banking.
We're talking about China, so that's probably not going to work: Chinese users are using Chinese browsers [1] to access Chinese websites. I don't think Chinese browser-makers and website operators are going to take action against their government like that.
[1] https://www.fastcompany.com/3058432/the-top-3-web-browsers-i...
It would mitigate attacks from inside China against outside entities, which for somebody not based in China is all I want.
> [Nicholas] Weaver said the attacks from the Great Cannon don’t succeed when people are browsing Chinese sites with a Web address that begins with "https://", meaning that regular Internet users can limit their exposure to these attacks by insisting that all Internet communications are routed over "https" versus unencrypted "http://" connections in their browsers. A number of third-party browser plug-ins — such as https-everywhere — can help people accomplish this goal.
> But Bill Marczak, a research fellow with Citizen Lab, said relying on an always-on encryption strategy is not a foolproof counter to this attack, because plug-ins like https-everywhere will still serve regular unencrypted content when Web sites refuse to or don’t offer the same content over an encrypted connection. What’s more, many Web sites draw content from a variety of sources online, meaning that the Great Cannon attack could succeed merely by drawing on resources provided by online ad networks that serve ads on a variety of Web sites from a dizzying array of sources.
[1] https://krebsonsecurity.com/2015/04/dont-be-fodder-for-china...
[1] https://news.ycombinator.com/item?id=21726617
> and in case I'm totally wrong, what mitigations are feasible? More trade war such as by compelling ISP's to null-route Chinese businesses like Baidu.com as a form of sanction?
Probably something like this, but I'm afraid of where that would lead.
> In cryptography, forward secrecy (FS), also known as perfect forward secrecy (PFS), is a feature of specific key agreement protocols that gives assurances that session keys will not be compromised even if the private key of the server is compromised.[1] Forward secrecy protects past sessions against future compromises of secret keys.[2][3][3]
* https://en.wikipedia.org/wiki/Forward_secrecy
There's still the risk of MITM identity spoofing of course.
Ultimately, if an attacker has all your keys and controls all your traffic, there's nothing left that distinguishes the attacker from you. No security is possible in that scenario.
Then they can view the traffic even going to and from foreign sites who would not comply with an order to share private keys and no safe browsing blacklist (like that would be accessible from inside the regime anyway) will help you.
If I'm understanding other comments correctly, browser vendors installing HTTPSEverywhere cuts down the potential for this Great Cannon attack from 7.7 billion users to 1.4 billion. An 80% reduction seems significant.
Addressed here: https://news.ycombinator.com/item?id=21721843
>Shit, they can require vendors include a hardware backdoor, especially since so much of that hardware is produced domestically.
If they're only doing it for local computers, the consequences/response is the same as the previous paragraph.
If they're doing it for foreign computers on a mass scale required for a DDoS attack, if discovered will torpedo their entire electronics sector. All the "ban huawei" politicians will have a field day with that.
https://developer.mozilla.org/en-US/docs/Web/Security/Same-o...
"Mitigations
These attacks would not be successful if the following resources were served over HTTPS instead of HTTP:
http://push.zhanzhang.baidu.com/push.js; orhttp://js.passport.qihucdn.com/11.0.1.js
You may want to consider blocking these URLs when not sent over HTTPS."
sudo echo -e "\n\n# Null route the Great Cannon:\n0.0.0.0 baidu.com\n0.0.0.0 qihucdn.com\n" | tee /etc/hosts
... but I know I'm only fooling myself.thanks (I admit didn't test it because I use `python3 ./updateHostsFile.py` to take care of /etc/hosts)
A slightly less broad measure that's just as effective would be to block unencrypted http traffic from entering China. Want to get unblocked? Get letsencrypt.
A even better (but slightly greyhat) route would be to inject HSTS headers with the maximum expiry date. This will cause any visitor's browsers to get "infected" with an unskippable warning, forcing them to upgrade no matter what.
Browsers are already moving to explicitly label HTTP sites as "not secure"