[HN Gopher] The Internet Shutdown Game
___________________________________________________________________
The Internet Shutdown Game
Author : pabs3
Score : 54 points
Date : 2023-12-08 08:40 UTC (14 hours ago)
(HTM) web link (shutdowngame.apc.org)
(TXT) w3m dump (shutdowngame.apc.org)
| renegat0x0 wrote:
| Nothing seems more legit than a zip file from a random site. I am
| grateful that it did not contain any executable file, but I think
| pdf files also can spread viruses.
| foobarbecue wrote:
| You're complaining that the file is compressed...? You don't
| trust your unzip software?
|
| How would you prefer they distribute the files?
| spacebacon wrote:
| Carrier pigeons at this point. He's right you know.
| sonicanatidae wrote:
| Pigeons can be infected with viruses.
|
| If we're really going to do this right, then Smoke Signals
| are the way. We take the 1s and 0s and encrypt them into
| different 1s and 0s to obfuscate. ;)
| renegat0x0 wrote:
| There seems to be no need for ZIP. There seems to be no need
| for PDFs in it. Everything that is in PDF most likely could
| be presented by webpage/HTML/etc. Therefore yes, I complain
| that the files are compressed.
|
| The need of downloading anything might be the point of that
| game, but people spreading viruses also like playing that
| way.
| foobarbecue wrote:
| -\\_(tsu)_/- I trust my unzip utility and my pdf viewer
| just as much as I trust my browser.
|
| I might have agreed with you 15 years ago, back in the age
| of antivirus and such.
| ziddoap wrote:
| > _I trust my unzip utility and my pdf viewer just as
| much as I trust my browser._
|
| The parent commenter is suggesting the random file may be
| malicious, not that their unzip utility or pdf viewer is
| untrustworthy.
|
| They are further suggesting that the data contained
| within the zip could be distributed in a fashion that is
| less commonly weaponized (PDF is a common attack vector,
| zip is a common obfuscation method).
|
| > _I might have agreed with you 15 years ago, back in the
| age of antivirus and such._
|
| What does this even mean? You still need antivirus today.
| sonicanatidae wrote:
| With their final statement, I think they are essentially
| stating that AV was a better shield 15 years ago and I
| don't disagree in a general sense.
|
| Today's AV has to be more than it was in the past to be a
| successful shield, hence products like CYNET or
| CrowdStrike.
|
| I still run AV at home on all systems, because I agree
| with you. AV is still needed and people without
| it...well, I wish them success.
| ElectricalUnion wrote:
| > The need of downloading anything might be the point of
| that game, but people spreading viruses also like playing
| that way.
|
| I think that you underestimate the capabilities of modern
| malware, and overestimate the capabilities of the average
| lazy person.
|
| Modern malware doesn't need this "download and execute"
| flow to activate. It exploits vulnerabilities in browsers
| and browser components to achieve arbitrary code execution.
| One click required (the one that leads you to the malware)
| [1].
|
| A malware flow with manual downloading that leaves
| persistent breadcrumbs on your computer has more
| opportunities where a "real-time protection" antivirus can
| detect and stop the threat, so it's no longer the norm
| outside email attachments.
|
| [1] https://github.blog/2023-09-26-getting-rce-in-chrome-
| with-in...
| inanutshellus wrote:
| I don't see how what you're proposing makes sense.
|
| It can't provide value to laypeople who're cutoff from the
| internet if all that's passed around is a URL.
| ElectricalUnion wrote:
| A random site with "just html" has the possibility as well to
| "spread viruses" with a unknown zero-day with for example a
| image handling exploit, or a novel sort of ram rewriting
| attack.
|
| If you really care about "casual usability of things that can
| spread viruses" in your security model, you would actually
| prefer documents in PDF format and running them thru Qubes
| sanitizing conversion appvm.
| kevincox wrote:
| Both Chromium and Firefox also have built-in PDF readers that
| run in the browser sandbox so you can read PDFs with no more
| attack surface than the webpage that you downloaded them from
| has access to. Of course a separate VM is going to be even
| more secure but it is a much bigger step for the average
| user.
| ElectricalUnion wrote:
| It all depends on your Operations Security model. For some
| people it's more important for things to be available and
| convenient that for them to be secure.
|
| For the average user, I would say malware running under the
| browser sandbox within a domain context is game over,
| assuming for example malware under your webmail or bank
| page domain.
|
| This XKCD applies to this very well: https://xkcd.com/1200/
|
| > If someone steals my laptop while I'm logged in, they can
| read my email, take my money, and impersonate me to my
| friends, but at least they can't install drivers without my
| permission.
| ppergame wrote:
| Each browser tab and cross-origin iframe is its own
| process sandbox. Web security operates on domain
| boundaries.
|
| If your webmail provider or bank is serving malware or
| user generated content under the same origin as the
| frontend, they have self-owned beyond the browser's
| capacity to help.
| autoexec wrote:
| > A random site with "just html" has the possibility as well
| to "spread viruses" with a unknown zero-day with for example
| a image handling exploit, or a novel sort of ram rewriting
| attack.
|
| Technically possible, but the vast majority of sites that can
| get you infected just by viewing them depend on JS. I'd much
| sooner trust an HTML document than a PDF file from some
| random website.
| diyseguy wrote:
| I always run any zip/pdf file through
| https://www.virustotal.com/gui/home/upload
| ChrisArchitect wrote:
| APC? I thought maybe this was presented by the backup power/UPS
| company. Not the Association for Progressive Communications.
| myself248 wrote:
| Clearly the situation can be resolved by throwing Armored
| Personnel Carriers at it.
| hejira wrote:
| Haha, my thoughts too! :D
| ale42 wrote:
| Lol, didn't know the latter, I though too it was APC (the UPS
| company) and that shutdowns were about power outages and how
| they relate to UPSs...
| HenryBemis wrote:
| To those worried, I can suggest www.virustotal.com
|
| When I download a file of uncertain origin/quality I always
| upload it there and rest (relatively) easy on what's in it.
| Kwpolska wrote:
| Sounds like a very slow and boring game. See a scenario of some
| Internet blocking, discuss for 10 minutes within teams, pick 1
| out of 8 cards that can circumvent the block.
| helios_invictus wrote:
| I play tested this at the Global Gathering in Portugal earlier
| this year! This little IRL group game is super cool way to learn
| about Internet shutdowns and how to work around them! Pushing all
| the poo-pooing aside this game was actually really fun, and a
| delightful educational game! It's a great way to talk about
| Internet shutdowns and circumventions with most people. Also the
| crew that put it together put in some very solid work to make
| this a smooth educational tool. Please don't be negative because
| the delivery method doesn't check all your boxes.
| hejira wrote:
| Thanks for a more contructive comment than most!
| zug_zug wrote:
| Would love a few sentence overview of the shutdown techniques and
| the workarounds
___________________________________________________________________
(page generated 2023-12-08 23:01 UTC)