The reason it is powerful is not this particular attack. It's a demonstration that they are willing and able to inject malicious responses to any request going to a Chinese resource (web site, analytics service, ads, etc.). Imagine if instead of returning some DoS javascript they deliver a payload to silently exploit a vulnerability in your browser/OS (and they are surely capable of finding or purchasing those) to do whatever they want with it:
- Add it to a botnet
- Steal your personal data
- Infiltrate your corporate network
- Wipe your system (punishment for those accessing or producing GFW circumvention software)
Are you confident your browser never makes HTTP requests to Chinese servers? Are there tools we can install to prevent it?
[EDIT: It looks like two separate HN stories got merged, and the comments along with them. Didn't know that could happen, but this comment now appears twice here.]