TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

If your site does not use HTTPS, Rostelecom will insert pro-war propaganda in it

36 点作者 anonymfus将近 3 年前

7 条评论

jordemort将近 3 年前
This sort of thing is why I look askance at the "you don't need certificates" crowd. In the US, at least both Comcast and AT&T have a long and well-documented history of injecting advertisements into websites when the lack of a certificate lets them get away with it. Maybe you don't care about eavesdroppers, but you should care about a malicious network tampering with your content in-flight.
vfclists将近 3 年前
Mobile providers have been doing this crap for ages.<p>That is why in the past I run my mobile connection through a VPN as much was possible.<p>FWIW this has nothing to do with pro-war propaganda, just the sketchy behaviour telecoms providers have been doing and still do.
评论 #32002256 未加载
MarkusWandel将近 3 年前
How easy is it, in practice, for a nation state level authority to add a root certificate to people&#x27;s devices?<p>Adding letsencrypt to my personal server made me realize that if I&#x27;m MITM&#x27;d by a proxy, the padlock still shows up; merely clicking on it and going down a couple of menu levels (in Chrome &quot;Connection is secure -&gt; Certificate is valid&quot; will reveal that the MITM proxy&#x27;s root certificate is in use.<p>If an employer can do this to its laptops, and presumably a cell phone maker to the cell phones it sells, just much protection does https really give you against a nation state level propaganda machine?
评论 #32006025 未加载
评论 #32012405 未加载
memen将近 3 年前
In cryptography there is the clear difference between encrypting and signing (Confidentiality and Integrity). Is this distinction possible on a webserver&#x2F;browser? I.e. No encryption, no signing -&gt; HTTP Encryption and signing -&gt; HTTPS No encryption, signing -&gt; ? What about public information (not confidential) that needs verification (yes integrity)?
评论 #32002532 未加载
评论 #32033446 未加载
mikecoles将近 3 年前
Even with HTTPS, are any pinning techniques still viable to warn users the traffic is being, possibly legitimately, MITM-ed?<p>HPKP was an option, but the footgun reason was given for dropping support. Has anything taken its place? Is there anyway to determine a MITM server-side without relying on x-forwarded-for or via headers?
spaceheater将近 3 年前
Author himself links to articles how said ISP was injecting news ads, since 2020. Current news is about Ukraine, thus must be propaganda.
评论 #32002302 未加载
PaulHoule将近 3 年前
Good way to make people switch.
评论 #32001351 未加载