China's Great Cannon: SAFENetwork as a tool to defuse cyber war escalation

As with the US, UK and others, China has developed offensive cyber warfare capabilities. Unlike the NSA, they made a public show of their latest tool, now being called China’s Great Cannon by researchers.

Perhaps one of SAFENetwork’s great benefits is protecting civilians from offensive cyber warfare such as DDoS attacks on essential online infrastructure, as well as from oppressive mass surveillance, censorship and criminal hackers. Side note: Martin Armstrong has recently speculated that a recent run of massive power blackouts might be the result of cyber attacks rather than the mundane faults reported by affected governments (US, Italy, Holland and Turkey).

Protection from cyber warfare is an increasingly important issue, and SAFE Network is neatly poised to ride to the rescue! :slight_smile:

China’s Great Cannon:

On March 16, GreatFire.org observed that servers they had rented to
make blocked websites accessible in China were being targeted by a
Distributed Denial of Service (DDoS) attack. On March 26, two GitHub
pages run by GreatFire.org also came under the same type of attack.
Both attacks appear targeted at services designed to circumvent Chinese
censorship. A report released by GreatFire.org fingered malicious
Javascript returned by Baidu servers as the source of the attack.1 Baidu denied that their servers were compromised.2
Several previous technical reports3
have suggested that the Great Firewall of China orchestrated these
attacks by injecting malicious Javascript into Baidu connections. This
post describes our analysis of the attack, which we were able to observe
until April 8, 2015.
We show that, while the attack infrastructure is co-located with the Great Firewall, the
attack was carried out by a separate offensive system, with different
capabilities and design, that we term the “Great Cannon.” The Great
Cannon is not simply an extension of the Great Firewall, but a distinct
attack tool that hijacks traffic to (or presumably from) individual IP
addresses, and can arbitrarily replace unencrypted content as a man-in-the-middle.
The operational deployment of the Great Cannon represents a
significant escalation in state-level information control: the
normalization of widespread use of an attack tool to enforce censorship
by weaponizing users. Specifically, the Cannon manipulates the traffic
of “bystander” systems outside China, silently programming their
browsers to create a massive DDoS attack. While employed for a highly
visible attack in this case, the Great Cannon clearly has the capability
for use in a manner similar to the NSA’s QUANTUM system,4
affording China the opportunity to deliver exploits targeting any
foreign computer that communicates with any China-based website not
fully utilizing HTTPS.

6 Likes

It’s a bit childish of governments to behave like teenage hackers, but ok all those kinds of attacks actually push information systems to become more resilient.

And if the cyber wars start to escalate out of control, then the SAFE network and other technologies like that will take over.

1 Like

A large percentage of the population will think “if I’m not doing anything wrong, then I don’t care if my government is sifting my communications data.” and “out of sight out of mind”. For now, the vast majority of web surfers do not care about security until their PC is infected and they discover their computer has a virus. Then they will look for a solution. If their computer is just slow, and importantly s/he does not know a virus or malware is slowing their computer, the user will not investigate, and in turn not care about their security and privacy as much as s/he should.

It will be very interesting to witness how the balance will play out, between IT security awareness among the majority, versus the level of sophisticated malware that can remain undetected.

Having said all this, I strongly believe that in the coming decade, education among the majority will increase and privacy and data security will become a higher priority in everyone’s minds. This is why I see MaidSAFE’s massive potential.

2 Likes