[HN Gopher] The Internet Shutdown Game
       ___________________________________________________________________
        
       The Internet Shutdown Game
        
       Author : pabs3
       Score  : 54 points
       Date   : 2023-12-08 08:40 UTC (14 hours ago)
        
 (HTM) web link (shutdowngame.apc.org)
 (TXT) w3m dump (shutdowngame.apc.org)
        
       | renegat0x0 wrote:
       | Nothing seems more legit than a zip file from a random site. I am
       | grateful that it did not contain any executable file, but I think
       | pdf files also can spread viruses.
        
         | foobarbecue wrote:
         | You're complaining that the file is compressed...? You don't
         | trust your unzip software?
         | 
         | How would you prefer they distribute the files?
        
           | spacebacon wrote:
           | Carrier pigeons at this point. He's right you know.
        
             | sonicanatidae wrote:
             | Pigeons can be infected with viruses.
             | 
             | If we're really going to do this right, then Smoke Signals
             | are the way. We take the 1s and 0s and encrypt them into
             | different 1s and 0s to obfuscate. ;)
        
           | renegat0x0 wrote:
           | There seems to be no need for ZIP. There seems to be no need
           | for PDFs in it. Everything that is in PDF most likely could
           | be presented by webpage/HTML/etc. Therefore yes, I complain
           | that the files are compressed.
           | 
           | The need of downloading anything might be the point of that
           | game, but people spreading viruses also like playing that
           | way.
        
             | foobarbecue wrote:
             | -\\_(tsu)_/- I trust my unzip utility and my pdf viewer
             | just as much as I trust my browser.
             | 
             | I might have agreed with you 15 years ago, back in the age
             | of antivirus and such.
        
               | ziddoap wrote:
               | > _I trust my unzip utility and my pdf viewer just as
               | much as I trust my browser._
               | 
               | The parent commenter is suggesting the random file may be
               | malicious, not that their unzip utility or pdf viewer is
               | untrustworthy.
               | 
               | They are further suggesting that the data contained
               | within the zip could be distributed in a fashion that is
               | less commonly weaponized (PDF is a common attack vector,
               | zip is a common obfuscation method).
               | 
               | > _I might have agreed with you 15 years ago, back in the
               | age of antivirus and such._
               | 
               | What does this even mean? You still need antivirus today.
        
               | sonicanatidae wrote:
               | With their final statement, I think they are essentially
               | stating that AV was a better shield 15 years ago and I
               | don't disagree in a general sense.
               | 
               | Today's AV has to be more than it was in the past to be a
               | successful shield, hence products like CYNET or
               | CrowdStrike.
               | 
               | I still run AV at home on all systems, because I agree
               | with you. AV is still needed and people without
               | it...well, I wish them success.
        
             | ElectricalUnion wrote:
             | > The need of downloading anything might be the point of
             | that game, but people spreading viruses also like playing
             | that way.
             | 
             | I think that you underestimate the capabilities of modern
             | malware, and overestimate the capabilities of the average
             | lazy person.
             | 
             | Modern malware doesn't need this "download and execute"
             | flow to activate. It exploits vulnerabilities in browsers
             | and browser components to achieve arbitrary code execution.
             | One click required (the one that leads you to the malware)
             | [1].
             | 
             | A malware flow with manual downloading that leaves
             | persistent breadcrumbs on your computer has more
             | opportunities where a "real-time protection" antivirus can
             | detect and stop the threat, so it's no longer the norm
             | outside email attachments.
             | 
             | [1] https://github.blog/2023-09-26-getting-rce-in-chrome-
             | with-in...
        
             | inanutshellus wrote:
             | I don't see how what you're proposing makes sense.
             | 
             | It can't provide value to laypeople who're cutoff from the
             | internet if all that's passed around is a URL.
        
         | ElectricalUnion wrote:
         | A random site with "just html" has the possibility as well to
         | "spread viruses" with a unknown zero-day with for example a
         | image handling exploit, or a novel sort of ram rewriting
         | attack.
         | 
         | If you really care about "casual usability of things that can
         | spread viruses" in your security model, you would actually
         | prefer documents in PDF format and running them thru Qubes
         | sanitizing conversion appvm.
        
           | kevincox wrote:
           | Both Chromium and Firefox also have built-in PDF readers that
           | run in the browser sandbox so you can read PDFs with no more
           | attack surface than the webpage that you downloaded them from
           | has access to. Of course a separate VM is going to be even
           | more secure but it is a much bigger step for the average
           | user.
        
             | ElectricalUnion wrote:
             | It all depends on your Operations Security model. For some
             | people it's more important for things to be available and
             | convenient that for them to be secure.
             | 
             | For the average user, I would say malware running under the
             | browser sandbox within a domain context is game over,
             | assuming for example malware under your webmail or bank
             | page domain.
             | 
             | This XKCD applies to this very well: https://xkcd.com/1200/
             | 
             | > If someone steals my laptop while I'm logged in, they can
             | read my email, take my money, and impersonate me to my
             | friends, but at least they can't install drivers without my
             | permission.
        
               | ppergame wrote:
               | Each browser tab and cross-origin iframe is its own
               | process sandbox. Web security operates on domain
               | boundaries.
               | 
               | If your webmail provider or bank is serving malware or
               | user generated content under the same origin as the
               | frontend, they have self-owned beyond the browser's
               | capacity to help.
        
           | autoexec wrote:
           | > A random site with "just html" has the possibility as well
           | to "spread viruses" with a unknown zero-day with for example
           | a image handling exploit, or a novel sort of ram rewriting
           | attack.
           | 
           | Technically possible, but the vast majority of sites that can
           | get you infected just by viewing them depend on JS. I'd much
           | sooner trust an HTML document than a PDF file from some
           | random website.
        
         | diyseguy wrote:
         | I always run any zip/pdf file through
         | https://www.virustotal.com/gui/home/upload
        
       | ChrisArchitect wrote:
       | APC? I thought maybe this was presented by the backup power/UPS
       | company. Not the Association for Progressive Communications.
        
         | myself248 wrote:
         | Clearly the situation can be resolved by throwing Armored
         | Personnel Carriers at it.
        
           | hejira wrote:
           | Haha, my thoughts too! :D
        
         | ale42 wrote:
         | Lol, didn't know the latter, I though too it was APC (the UPS
         | company) and that shutdowns were about power outages and how
         | they relate to UPSs...
        
       | HenryBemis wrote:
       | To those worried, I can suggest www.virustotal.com
       | 
       | When I download a file of uncertain origin/quality I always
       | upload it there and rest (relatively) easy on what's in it.
        
       | Kwpolska wrote:
       | Sounds like a very slow and boring game. See a scenario of some
       | Internet blocking, discuss for 10 minutes within teams, pick 1
       | out of 8 cards that can circumvent the block.
        
       | helios_invictus wrote:
       | I play tested this at the Global Gathering in Portugal earlier
       | this year! This little IRL group game is super cool way to learn
       | about Internet shutdowns and how to work around them! Pushing all
       | the poo-pooing aside this game was actually really fun, and a
       | delightful educational game! It's a great way to talk about
       | Internet shutdowns and circumventions with most people. Also the
       | crew that put it together put in some very solid work to make
       | this a smooth educational tool. Please don't be negative because
       | the delivery method doesn't check all your boxes.
        
         | hejira wrote:
         | Thanks for a more contructive comment than most!
        
       | zug_zug wrote:
       | Would love a few sentence overview of the shutdown techniques and
       | the workarounds
        
       ___________________________________________________________________
       (page generated 2023-12-08 23:01 UTC)