[1] http://www.theregister.co.uk/2015/03/27/github_under_fire_fr...
[1] http://www.theregister.co.uk/2015/03/27/github_under_fire_fr...
At some point it's going to make more economical sense to kick China of the internet.
Careful with that, because the moment some nation can kick out another nation out of the internet for whatever reason we're toasted.
Plus, it's better to wait and see some hard evidence (if any can be found) before jumping into conclusions.
Well, that's exactly what the DDoS wanted, so the government could just happily control all access to Internet in mainland China
The DDoS targets github.com/greatfire and github.com/cn-nytimes by their so called "collateral freedom" [1]
Suppose github could just ban Chinese IP all together, but @greatfire could easily jump to another host and abuse ToS to hosting "neutral" political content, like bitbucket[2]
Many webmasters have already banned all Chinese IPs, so gradually, every public hosting service will eventually ban all Chinese IPs, Chinese government could easily destroy the rest of circumvention methods
[1]: https://en.greatfire.org/blog/2014/jan/collateral-freedom-fa...
What it was actually doing was a massive MITM attack against non-SSLd HTTP connections from inbound connections to China, from Chinese users abroad visiting Chinese websites. It's an extremely clever trick that is only possible if you have the ability to mount mass MITM attacks on an entire country, but what it gives you is a massive ever shifting botnet.
The lesson I draw from this is that we need more SSL, we need it everywhere and we need it yesterday. I hope this stuff puts to rest the idea that some websites aren't worth being encrypted.
If the encryption is then broken and it is done again, then a) it will prove that China did it. Because you can see who signed the certificate. b) it will prove that technical countermeasures are not enough, since the problem is deeper than that.
Because someone might like to mess with train signals, and in the off chance that some weakness is found in the MAC/signature scheme you're using, forcing an attacker to guess at which messages they're manipulating and how will make their attack more difficult.
If you're working with a networked application, even if it's on a non-public network, you should be asking yourself "why not encrypt?" instead of "why encrypt?". This is doubly true of critical infrastructure that's expensive and slow to replace.
* For definitions of "Chinese government" that includes the Beijing non-profit China Internet Network Information Center, which isn't technically part of the government, but presumably is easily pressured.
* * For definitions of "all browsers" that excludes some minority browsers and those browsers run by users who have disabled the CNNIC root cert.
I have no doubt that the Chinese government has access to the CCNIC root certificate private key if it so chooses, but demanding the private key for an existing domain certificate would provide slightly less traceability and slightly more deniability.
FTFY
BTW: Here is the Cloudflare way:
arse | ass
That's optional, so we have the regular expression: (arse|ass)+
Put back the "holes" and we get the regular expression: (arse|ass)+holes
Clear?I'll leave my comment there as a testament to writing from memory and experience, rather than taking the time to check modern standards, and how things might have changed.
Thank you.
Is how i would write it, +/- a case insensitive flag.
Think about it: the government wants to cut us off from the rest of the world, that would make them happy, but would PISS a lot of people off. Anyways, if the westerners did it for the Chinese government, the people would be angry at them rather than the government...
If you try to complain to China Telecom about not being able to access Facebook, they already blame it Facebook since none of these sites are "officially" blocked. This would just play into that lie big time.
Chinas ability to manufacture and sell hinges critically on internet connectivity. Of all the sanctions that would be effective I think an internet blockade is one of the more practical and effective ones.
Let's just please not go there.
One day we're advocating net neutrality and the next day we want to ban entire countries from the internet? I still prefer net neutrality, thank you.
If it was simply "about" that, then that would include DDOS traffic. Which no one in their right mind wants to treat equally.
Worms, meet can.
You want the people in China consuming more and not less of it.
Want all you wish, the Chinese government is actively stopping and blocking the outside internet at an alarming rate. I was in Beijing a few weeks ago and couldn't load google, youtube, gmail, gmaps, instangram, facebook, twitter, various chatting apps, imgur, and on and on. Even using VPNs were difficult. I don't see this stopping anytime soon since it allows 1) control of the people and 2) growth from copying a western products and forcing the people inside the firewall to use the Chinese cloned version.
By "rest of world" do you mean the USA? Or Europe? Or basically "the west"?
When does it sound like cultural imperialism?
Are countries (and their citizens) only permitted to be connected to the internet if their culture matches that of your country/federation?
How is that not an offensive idea?
Usually, I reverse statements and if I find them offensive in reverse they are probably offensive full stop. This one is pretty offensive.
Don't be so easily offended. Nobody said anything about their culture. The reason the question is being raised is because of the unignorable number of DDOS attacks being launched from their Internet space. Stop that, and you'll have less calls for cutting their connection.
Which is quite unlikely. We don't kick out USA because NSA breaks into backbone routers, steal encryption codes from sim cards, and steal traffic from google search, Gmail and Facebook. China attacks github, and the reaction will be likely the same.
At some point, it is going to make a economical sense to issue a treaty against this kind of behaviors. A treaty that forbids attacking fellow nations infrastructure and businesses over the Internet will benefit everyone, and it is going to take a long time before it is commonly understood.
I was also under the impression that this is already in violation of treaty, the only saving grace for the PRC being that it hasn't been proven it's them.
Remotely transmitted malware.
Hardware caught in transit and infected by malware.
Firmware infected with malware at factories.
Bricked backbone routers, causing widespread outage during civil war.
Hacked phone companies.
Stuxnet, a computer worm designed to sabotage industrial centrifuges.
A $6 billion trade contract being manipulated in favor of Boeing.
A $1.3 billion contract trade contract being manipulated in favor of American defense contractor Raytheon.
Weakening products and standards that Internet users.
Should I continue? The list goes on and on and on as more leaks are reported on. Using that definition of snooping, we can just call PRC action snooping too.
For data acquisition (snooping).
> Hardware caught in transit and infected by malware.
For... hmm... backdoors to data? (Laptops with Stuxnet covered below)
> Firmware infected with malware at factories.
For, yes, transmission snooping. The PRC has also altered routers and other computerized electronics, including those intended for use by militaries in various Western countries.
> Bricked backbone routers, causing widespread outage during civil war.
Yes, by accident [1] while attempting to surveil (snoop). Not sure if disabling Syria's internet is worse or better than China's DNS poisoning which affected everyone... by accident.
> Hacked phone companies.
For what purpose, I wonder?
> Stuxnet, a computer worm designed to sabotage industrial centrifuges.
A. Not done over the internet, done by sneakernet. B. Nuclear reactor facilities in Iran are really not the same as GitHub.
> A $6 billion trade contract being manipulated in favor of Boeing.
That's nefarious, I'll agree... except, the NSA just blew the whistle on Airbus who was bribing Saudi officials. The information was indeed gained from--wait for it--snooping. [2]
> ...Raytheon
Same deal there... The CIA was the whistle blower against the French competition. [3]
> Weakening products and standards that Internet users.[sic]
LOL.
Of the two actions you do cite that aren't surveillance, one has nothing to do with the internet and the other was for the purpose of surveillance. So no, the U.S. government's surveillance program is not the same as the PRC performing a DDoS attack on Github.
[1] http://gizmodo.com/snowden-the-nsa-turned-off-syrias-internet-1621068611
[2] http://news.bbc.co.uk/2/hi/europe/820758.stm
[3] http://en.wikipedia.org/wiki/ECHELON#cite_note-60Backdoors has a lovely side effect, in that they are backdoors. They can be used to take control over devices, as in. That they can also be used for data transfer is a side effect of the active attack called "implanting an backdoor".
But okey, if all those are just snooping and not active attacks, let just assume that PRC gained the information to attack github by snooping. DONE. It is now just snooping as per your definition.
> A DDOS attack on github.
>> except, the PRC just used information, information which was indeed gained from--wait for it--snooping!
In computer security, we have terms to distinguish this. Its called passive and active attacks. PRC and NSA both perform active attacks on other nations infrastructure, businesses, governments and military. The purpose: To gain political, economic and military benefits.
This attack is a clumsy way to harass those projects. It's not sure to work, and is bringing the specific projects more attention in the meantime. As an official (or easily-attributable) extra-territorial action, it seems both unprecedented and disproportionate.
It's also drawing extra attention to the border machines and their capability to do man-in-the-middle tampering. I'd have thought CNGov would want to be miserly with that capability, to suppress awareness of the risk or development of countermeasures/workarounds.
I wouldn't completely rule out that this might be an action by some other party that intends, in a roundabout way, to raise an alarm about Chinese net borders.
They've been redirecting traffic of its user to load GitHub, which is a very smart/evil tactic to use - this is what certain sites did years ago to take down their smaller competitors.
Basically the government doesn't really care what other people do outside the Chinese Internet, and just block anything they don't want local people to read.
Far more likely is a 'red hacker', e.g. Someone hacking for patriotic reasons and has taken issue with those projects hosted on GitHub.
It may well be that the person has government connections or works in some way for the government but I'd be surprised if it was a government sponsored/sanctioned attack - especially because there are far more likely candidates who will be far easier to take offline than GitHub.
The Chinese government's strategy has generally been about keeping things out, not taking things down.
I might not have lived in and researched China for 28 years, but I'm not exactly a stranger to the place and have spent the better part of a decade in China and the greater China area and have been circumventing the great firewall for almost 15 years.
Unless your China research has been limited to something like the tea cultivating habits of the Bulang minority, you should be able to list off the top of your head a half dozen better targets than the current attack, which is two relatively small projects, largely unknown to the Chinese people, and hosted on another website (GitHub) that is once again largely unknown to majority of Chinese Internet users.
I still stand by my statement that the Chinese government doesn't really care what the rest of the world reads/watches so long as they can control what their local citizens have access too.
If the Chinese government wanted those projects gone they would just block those project pages. Their current infrastructure is more than sufficient to do that both from a technical perspective in blocking just those projects rather than the entire GitHub domain, and from a man power perspective (tens of thousands of people employed to monitor the web for 'objectionable' content).
If the government was really interested in knocking material they find objectionable off the internet through a DDoS then thanks to the GFW they already have a big list of sites and content they don't like and they could take the total GitHub DDoS traffic and proportion it among the top however many sites they don't like and bring them down far more easily than bringing down GitHub, and with far less people caring about it.
P.S. If you want me to take you seriously as an expert on China, you probably shouldn't put google-translated Chinese messages on your twitter feed.
Yes you could change wording up, but then you run the risk of either obfuscating it too much that users of the program don't how to find it, or the government updating filters to block the changes content also.
Groups with real desire to circumvent the GFW have other ways to do it. I've been use ssh tunnelling for almost 15 years without major issues.