Captcha.nsa.gov
captcha.nsa.gov
captcha.nsa.gov
Edit: This seems to have been online since 2018, see https://web.archive.org/web/20181206224407/http://captcha.ns....
The legit explanation (given the domain name) is probably they wanted to use reCAPTCHA, but block all non-NSA hosts with a firewall or something.
This is not great, because the NSA expanded its attack surface to all of google.com.
The more conspiracy explanation is that this is actually a phishing page set up, and due to a misconfiguration it's exposed under captcha.nsa.gov, but Occam's Razor should apply here.
That's one plausible explanation, but in any case, even if my explanation is wrong, I doubt the explanation is interesting.
Gmail by NSA: https://captcha.nsa.gov/intl/us/gmail/about/
They're inheriting a considerable part of Google's attack surface. For example, Google's open redirects could be used to bypass origin checks as part of an attack on nsa.gov, or to phish NSA employees.
Google doesn’t, the reverse proxy just rewrites the Host header.
Maybe this is just a fake front page that calls to the Google search API and pretends to be Google proper. Either it is for agents in the field to inconspicuously use google or they misconfigured it to be public?
> Either it is for agents in the field to inconspicuously use google
By visiting a nsa.gov subdomain served by akamai? Yeah right. I feel like heading to www.google.com would be far less conspicuous.
At least that is my experience with proxying google services (e.g. silly setup for accessing them from China). Datacenter IPs or SSL "MitM" connections reliably trigger it.
Again I'm guessing it's because I was logged in, from google chrome.
This is working far faster now than when first posted.
https://developers.google.com/recaptcha/docs/v3#frontend_int...
Kind of related post: https://news.ycombinator.com/item?id=21582698
> $ dig captcha.nsa.gov
> ;; ANSWER SECTION:
> captcha.nsa.gov. 13246 IN CNAME www.nsa.gov.edgekey.net.
> www.nsa.gov.edgekey.net. 21528 IN CNAME e6655.dscna.akamaiedge.net.
> e6655.dscna.akamaiedge.net. 19 IN A 23.213.xxx.xxx
The IP addreses at the last one all seem to be Akamai IPs. So So that is fronting Google here it seems?
You can find more info about how that works here: https://en.wikipedia.org/wiki/Reverse_proxy
i.e. if I see you producing fake Coca Cola drinks, I can't sue you for infringing on The Coca Cola Company's trademark. They would have to sue you. Same applies for the government.
And of course, if NSA does have an agreement with Google to reverse proxy https://google.com/, them doing exactly that would be perfectly legal. I presume they have SOME sort of agreement, and aren't just doing this behind Google's back, as the website is on HN's first page in the first 5 places for an hour already, and Google hasn't banned access.
Try getting even 50 Google queries with a reverse proxy, and you will see what I mean -- they will show you a progressively more difficult ReCAPTCHA until a certain treshold, after which the CAPTCHA is unsolvable and is there only to waste your time. This hasn't happened to HN readers [yet].
that's definitely not what's happening here though, most obviously because it has an SSL certificate. If it were just being CNAMEd over to google, the SSL would be invalid. NSA has to be catching the request to terminate the SSL, and then proxying it back to google.
You can't search traceroute. Weird.
You can't have some strings in the URL for the main NSA.gov domain as well. So https://nsa.gov/fakething?hey=traceroute will give you the same error.
DNS Name=www.nsa.gov
DNS Name=nsa.gov
DNS Name=apps-test.nsa.gov
DNS Name=stage.nsa.gov
DNS Name=apps.nsa.gov
DNS Name=www2.nsa.gov
DNS Name=captcha.nsa.gov
DNS Name=m.nsa.gov
https://www.congress.gov/bill/115th-congress/house-bill/2331
>If, on or after the date that is 180 days after the date of the enactment of this section, an agency creates a website that is intended for use by the public or conducts a redesign of an existing legacy website that is intended for use by the public, the agency shall ensure to the greatest extent practicable that the website is mobile friendly.
E: sorry, HN is throttling me and I can’t reply below. This is just a silly web application firewall that blocks a list of “suspicious strings”. There’s not much else to be said about it.
Small chance, but in case anyone on HN is in a place google is blocked, would be an interesting test to run.
I am curious to see if it is blocked.
https://www.comparitech.com/privacy-security-tools/blockedin...
There is some truth to this.
$ host captcha.nsa.gov
captcha.nsa.gov is an alias for www.nsa.gov.edgekey.net.
www.nsa.gov.edgekey.net is an alias for e6655.dscna.akamaiedge.net.
e6655.dscna.akamaiedge.net has address 104.75.125.118
e6655.dscna.akamaiedge.net has IPv6 address 2600:1406:5800:7b5::19ff
e6655.dscna.akamaiedge.net has IPv6 address 2600:1406:5800:792::19ff
edgekey.net is an akamai thingy, all of nsa.gov seems to go through it $ host www.nsa.gov
www.nsa.gov is an alias for nsa.gov.edgekey.net.
nsa.gov.edgekey.net is an alias for e16248.dscb.akamaiedge.net.I see a google search page (google.com equivalent). Which fits with the reverse proxy that does ~any google url.
I wonder what other sites the nsa has active alerting on?
Perhaps they’re just using google.com like example.com, or they’re trying to serve recaptcha under nsa.gov.
Consider reporting this to Safe Browsing complaint form as phishing attempt: https://www.google.com/safebrowsing/report_phish/
It could have been part of a phishing setup that got accidentally pushed out with obfuscation components still missing.
It's not like everybody working at NSA is a flawless human being, mistakes happen everywhere, sometimes even rather big ones.
Also kinda weird how everybody seems to be giving the NSA the benefit of the doubt of this having some kind of supposedly totally benign purpose, completely ignoring the NSA's history and purpose.
EDIT: And now it's showing up in English.