TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

China Telecom's Internet Traffic Misdirection

410 pointsby dbelsonover 6 years ago

14 comments

restersover 6 years ago
Combine this with exploits into one or more broadly trusted certificate authorities (which surely exist) and it&#x27;s pretty amazing how much data China would have been able to obtain.<p>Every time I bring up the following point someone chimes in that it&#x27;s a bad idea, but I still fail to understand why it&#x27;s not easy to pick which CAs I want to trust by picking a list of entities&#x2F;people I trust and then adopting their recommendations for which CAs to trust.<p>This would be a few clicks of UI to let me be intelligently paranoid while maintaining only a layperson&#x27;s understanding of why (say) Bruce Schneier decides to trust some and not others.
评论 #18387958 未加载
评论 #18386833 未加载
评论 #18386994 未加载
评论 #18387461 未加载
评论 #18387237 未加载
评论 #18388944 未加载
评论 #18386623 未加载
评论 #18386723 未加载
评论 #18386497 未加载
commandlinefanover 6 years ago
I&#x27;m continually amazed at how insecure almost every aspect of internet routing is - it mostly boils down to a sort of &quot;gentlemen&#x27;s agreement&quot; that everybody will follow the rules.
评论 #18386337 未加载
评论 #18386307 未加载
评论 #18386440 未加载
评论 #18387726 未加载
评论 #18386321 未加载
评论 #18386495 未加载
cauldronover 6 years ago
CT and Chinese ISPs have been hijacking user traffic for decades, profiting off of it by selling traffic dump to data exploiting companies, insert ads in webpages, steal social media tokens (for follower boosting and ads retweeting).<p>I&#x27;ve found China Unicom openly hawking their data mining products. <a href="https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;uNxA50K" rel="nofollow">https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;uNxA50K</a>
评论 #18388706 未加载
burtonator2011over 6 years ago
This is one of the reasons TLS&#x2F;SSL and crypto is so amazingly important.<p>Go ahead, monkey around with BGP, since I have the public key of the recipient of my packets I can detect this and block any type of misdirection.
评论 #18386532 未加载
martinaldover 6 years ago
Somewhat offtopic but which tool shows you the AS number + info alongside the traceroute in the screenshot?
评论 #18389060 未加载
mirimirover 6 years ago
OK, so I&#x27;m sitting here, posting to HN in Firefox. And if I like, I can open a terminal and run something like:<p><pre><code> traceroute news.ycombinator.com | grep -f chinese-ipv4 -f chinese-hosts </code></pre> And indeed, there could be a Firefox extension that did that, right? So at least, users would know.
评论 #18391587 未加载
mehrdadnover 6 years ago
Tangent, but are traceroutes spoofable (barring timing differences), or would they break too many other things to be practical? I&#x27;m wondering if anyone might do that to hide their tracks.
评论 #18401456 未加载
localguyover 6 years ago
&quot;Loading...&quot; the page doesn&#x27;t work without JavaScript enabled for no reason.
评论 #18386437 未加载
评论 #18388219 未加载
walrus01over 6 years ago
If BGP4 were designed today, it would look very different.
zozbot123over 6 years ago
How about just globally blocking AS4134 and AS9318?
评论 #18389940 未加载
furkitolkiover 6 years ago
According to traceroute, I wonder what makes United States safe and China not. Both not safe.
ggmover 6 years ago
Hanlon&#x27;s razor has been raised on NANOG.
jmartricanover 6 years ago
This is so stupid that we keep doing business with the Communist Party of China.
评论 #18389195 未加载
评论 #18387733 未加载
评论 #18386342 未加载
gcb0over 6 years ago
lol. typical anachronistic oracle. their blog fails fail to render on 2 out of 3 browsers I tested. What is this? 1995?
评论 #18387537 未加载