China Is Said to Use Powerful New Weapon to Censor Internet(nytimes.com)
nytimes.com
China Is Said to Use Powerful New Weapon to Censor Internet
http://www.nytimes.com/2015/04/11/technology/china-is-said-to-use-powerful-new-weapon-to-censor-internet.html
3 comments
Comments moved to https://news.ycombinator.com/item?id=9353785.
Like I said in the other [1] thread on this topic, I hope that this drives home the need to be using HTTPS everywhere we can be. It would make this kind of wide scale man-in-the-middle attack much harder to pull off and easier for users to detect. If only getting a certificate was an easier (less costly) process.
[1] - https://news.ycombinator.com/item?id=9353785
[1] - https://news.ycombinator.com/item?id=9353785
I hope this drives home the need to stop including 3rd party javascript on websites. It makes visitors' browsers load and run code of variable trustworthiness. The browser sandbox is entirely ill-equipped to keep users safe and secure online or prevent their computers from being leveraged for malicious ends. The sandbox allows everything but the most indefensible exploitative actions.
HTTPS is great and all, and does change the threat model but the Chinese government controls root certificates your browser trusts. And they weren't worried about getting detected funneling traffic to github.
HTTPS is great and all, and does change the threat model but the Chinese government controls root certificates your browser trusts. And they weren't worried about getting detected funneling traffic to github.
Mentioned this yesterday, but Mozilla's got a free CA project that's supposed to be up in a few months. Hopefully we'll see some of the entrenched players burn^H^H^H^H get real competition now!
https://letsencrypt.org
https://letsencrypt.org
Crazy my friend Bill worked on this, he's the one pictured in the article