TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Captcha.nsa.gov

435 pointsby scblznover 5 years ago

39 comments

phlharover 5 years ago
Oh wow, they just disabled it while I was reading some comments. It&#x27;s no longer working, I&#x27;m now getting redirected to nsa.gov<p>Edit: This seems to have been online since 2018, see <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20181206224407&#x2F;http:&#x2F;&#x2F;captcha.nsa.gov&#x2F;" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20181206224407&#x2F;http:&#x2F;&#x2F;captcha.ns...</a>.
评论 #22228334 未加载
评论 #22234541 未加载
orishoover 5 years ago
I&#x27;m guessing that the NSA website uses recaptcha, which is served by Google. Perhaps in order to comply with strict origin policy, they want everything on nsa.gov to be served from their domain. They seem to have a reverse proxy that proxies requests to google.com.<p>That&#x27;s one plausible explanation, but in any case, even if my explanation is wrong, I doubt the explanation is interesting.
评论 #22227597 未加载
评论 #22230611 未加载
fredleyover 5 years ago
Can someone explain what&#x27;s going on? Is this a domain hack to get Google&#x27;s captcha working under an nsa.gov hostname, presumably so that it&#x27;s usable on whitelist firewalls? I&#x27;m surprised Google serves a homepage to the domain, and that it doesn&#x27;t only respond to requests to google.com (etc.)
评论 #22228000 未加载
评论 #22226846 未加载
评论 #22226688 未加载
评论 #22226777 未加载
评论 #22226721 未加载
Aissenover 5 years ago
I&#x27;ve seen this on Twitter all day. My guess is that they wanted recaptcha, but serving the resources themselves. The easiest route was probably to reverse proxy google.com, which is what recaptcha is hosted on:<p><a href="https:&#x2F;&#x2F;developers.google.com&#x2F;recaptcha&#x2F;docs&#x2F;v3#frontend_integration" rel="nofollow">https:&#x2F;&#x2F;developers.google.com&#x2F;recaptcha&#x2F;docs&#x2F;v3#frontend_int...</a>
评论 #22231840 未加载
评论 #22227508 未加载
kyrraover 5 years ago
Looks to be cname forwarding.<p>&gt; $ dig captcha.nsa.gov<p>&gt; ;; ANSWER SECTION:<p>&gt; captcha.nsa.gov. 13246 IN CNAME www.nsa.gov.edgekey.net.<p>&gt; www.nsa.gov.edgekey.net. 21528 IN CNAME e6655.dscna.akamaiedge.net.<p>&gt; e6655.dscna.akamaiedge.net. 19 IN A 23.213.xxx.xxx<p>The IP addreses at the last one all seem to be Akamai IPs. So So that is fronting Google here it seems?
评论 #22226772 未加载
评论 #22235190 未加载
kushaover 5 years ago
From this twitter thread: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;mikko&#x2F;status&#x2F;1224349151384821762" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;mikko&#x2F;status&#x2F;1224349151384821762</a><p>You can&#x27;t search traceroute. Weird.
评论 #22226794 未加载
评论 #22227119 未加载
评论 #22226791 未加载
评论 #22226826 未加载
评论 #22226783 未加载
DangerousPieover 5 years ago
Interesting alt names on the SSL certificate:<p>DNS Name=www.nsa.gov<p>DNS Name=nsa.gov<p>DNS Name=apps-test.nsa.gov<p>DNS Name=stage.nsa.gov<p>DNS Name=apps.nsa.gov<p>DNS Name=www2.nsa.gov<p>DNS Name=captcha.nsa.gov<p>DNS Name=m.nsa.gov
评论 #22227350 未加载
评论 #22226997 未加载
patorjkover 5 years ago
My first instinct is that this is some kind of puzzle. It&#x27;d be pretty disappointing if this was just a misconfiguration or oversight.
评论 #22226752 未加载
arayover 5 years ago
I&#x27;m curious if this is a (temporary, unsecure) way to use google if you&#x27;re in a place that google is currently blocked.<p>Small chance, but in case anyone on HN is in a place google is blocked, would be an interesting test to run.
评论 #22228203 未加载
评论 #22228218 未加载
KindOneover 5 years ago
NSA&#x27;s official statement on twitter:<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;NSAGov&#x2F;status&#x2F;1224456957622472706" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;NSAGov&#x2F;status&#x2F;1224456957622472706</a> (1&#x2F;2)<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;NSAGov&#x2F;status&#x2F;1224456959618945024" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;NSAGov&#x2F;status&#x2F;1224456959618945024</a> (2&#x2F;2)
preillymeover 5 years ago
Looks like the good folks over at the NSA are reading Hacker News. And fix issues quickly. I’m proud of them.
评论 #22230476 未加载
评论 #22230386 未加载
chillydawgover 5 years ago
So someone with control of a .google.com address can get a certificate for the equivalent .nsa.gov subdomain ?
coekieover 5 years ago
You can see what IP it uses to send requests to google using <a href="https:&#x2F;&#x2F;captcha.nsa.gov&#x2F;search?q=what+is+my+ip" rel="nofollow">https:&#x2F;&#x2F;captcha.nsa.gov&#x2F;search?q=what+is+my+ip</a>
评论 #22227466 未加载
1970-01-01over 5 years ago
NSA thanks you for you participation in this experiment. Please terminate all knowledge with the purple pill at this time.
评论 #22232918 未加载
867-5309over 5 years ago
it&#x27;s all a ploy to finger HN users. imagine how many uniques they&#x27;ll harvest!
评论 #22227711 未加载
greatjack613over 5 years ago
Can anyone from mainland china try this?<p>I am curious to see if it is blocked.
评论 #22227156 未加载
评论 #22227164 未加载
iodover 5 years ago
<a href="https:&#x2F;&#x2F;captcha.nsa.gov&#x2F;intl&#x2F;en&#x2F;about.html" rel="nofollow">https:&#x2F;&#x2F;captcha.nsa.gov&#x2F;intl&#x2F;en&#x2F;about.html</a><p>There is some truth to this.
评论 #22228341 未加载
ljdover 5 years ago
I feel like the valid SSL cert is my biggest issue here.
评论 #22226697 未加载
评论 #22226740 未加载
SubiculumCodeover 5 years ago
Why is everyone talking about a captcha? All I get is a google search page (no recaptchas).
评论 #22226863 未加载
评论 #22226911 未加载
parliament32over 5 years ago
It&#x27;s just a CNAME to an akamai IP:<p><pre><code> $ host captcha.nsa.gov captcha.nsa.gov is an alias for www.nsa.gov.edgekey.net. www.nsa.gov.edgekey.net is an alias for e6655.dscna.akamaiedge.net. e6655.dscna.akamaiedge.net has address 104.75.125.118 e6655.dscna.akamaiedge.net has IPv6 address 2600:1406:5800:7b5::19ff e6655.dscna.akamaiedge.net has IPv6 address 2600:1406:5800:792::19ff </code></pre> edgekey.net is an akamai thingy, all of nsa.gov seems to go through it<p><pre><code> $ host www.nsa.gov www.nsa.gov is an alias for nsa.gov.edgekey.net. nsa.gov.edgekey.net is an alias for e16248.dscb.akamaiedge.net.</code></pre>
alistairSHover 5 years ago
I don&#x27;t get it - I&#x27;m seeing a Brazilian version of Google?
Groxxover 5 years ago
I assume that the archive.org mirror is showing what was visible? <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20200203154312&#x2F;http:&#x2F;&#x2F;captcha.nsa.gov&#x2F;" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20200203154312&#x2F;http:&#x2F;&#x2F;captcha.ns...</a><p>I see a google search page (google.com equivalent). Which fits with the reverse proxy that does ~any google url.
fnord77over 5 years ago
NSA&#x27;s cert, too. All your are TLS belong to us.
cjjuiceover 5 years ago
A potential vector would be to potentially load images&#x2F;content through google image&#x2F;AMP and make it appear as legitimate NSA content
johnmarcusover 5 years ago
The creapiest thing to me is that this post is 7 hours old, and the comment states it&#x27;s disabled. It was fixed within 2 hours. Ergo, the NSA is actively monitoring HackerNews and taking quick actions when needed.<p>I wonder what other sites the nsa has active alerting on?
评论 #22231724 未加载
Paraestheticover 5 years ago
Doh, I was hoping for a captcha made by the NSA, for catching bots, and terrorists and such.
maxbainesover 5 years ago
Why Brazil?
评论 #22226859 未加载
ryanlolover 5 years ago
Nothing especially interesting happening here, someone just pointed captcha.nsa.gov at google.com in their akamai config.<p>Perhaps they’re just using google.com like example.com, or they’re trying to serve recaptcha under nsa.gov.
评论 #22226936 未加载
评论 #22226806 未加载
codefulover 5 years ago
No ads. Nice! :D
mnxover 5 years ago
It seems like we broke it -- it now refuses to do any searches for me (due to suspicious activity from &#x27;my&#x27; ip)
milankragujevicover 5 years ago
And it&#x27;s gone (redirects to nsa.gov)...
alpbover 5 years ago
It&#x27;s likely this is set up to collect data by impersonating Google Search in an iframe etc.<p>Consider reporting this to Safe Browsing complaint form as phishing attempt: <a href="https:&#x2F;&#x2F;www.google.com&#x2F;safebrowsing&#x2F;report_phish&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;safebrowsing&#x2F;report_phish&#x2F;</a>
评论 #22227158 未加载
sdinsnover 5 years ago
Why is it in Portuguese?
评论 #22226923 未加载
aussieguy1234over 5 years ago
A test version of a MITM proxy that captures data?
colejhudsonover 5 years ago
Just went down, now redirects to www.nsa.gov.
qubexover 5 years ago
I am somewhat baffled. What was that?
pamicelover 5 years ago
??????
romaaeternaover 5 years ago
This looks really really dumb. I wonder if you can get personal sites to display through nsa.gov somehow through this.
aloknnikhilover 5 years ago
Among other things, it&#x27;s weird that it shows up with a different GeoIP triangulation for different users. Someone commented here about seeing this in Portuguese. I&#x27;m seeing this in Japanese. Does anyone what&#x27;s going on?<p>EDIT: And now it&#x27;s showing up in English.
评论 #22227259 未加载
评论 #22227384 未加载