苹果iCloud在中国遭中间人攻击

Analyzer是GreatFire的第一个项目,在2011年上线后,它一如以往的为大家提供测试服务直至今日。现在,我们做了一个新的项目叫做"Blocky",欢迎大家试用这个全新的版本!如果您对此有任何意见和建议,请发送邮件到support@greatfire.org

中国当局对苹果的云服务iCloud发起中间人攻击(MITM)。此前,有调查显示,中国对Github、谷歌、雅虎和微软都发动了中间人攻击。此次对iCloud的中间人攻击,与此前对谷歌、Github和雅虎的攻击不同。此次对苹果的攻击,是为了盗取用户的登录名和密码,以及储存在iCloud上的所有数据,包括iMessage、照片、联络人等。

此次对苹果的攻击是全国性的,且发生在iPhone 6在中国开售首日(10月18日)。中国防火墙GFW正在通过一张假的安全证书,对苹果的iCloud发起中间人攻击。当局仅攻击了IP地址 23.59.94.46. 。并非中国大陆的所有用户都受到影响,因为iCloud的DNS服务器返回的IP地址可能不同。

icloud2.png

此前对谷歌和雅虎的中间人攻击,中国当局从中获取了中国网民这两个平台上所获得的信息。此次对苹果的攻击中,如果用户忽视安全警告,直接点进苹果网站并输入用户名和密码,他们的登入信息将被当局获取。许多苹果用户使用iCloud来存储个人信息,包括iMessages,照片和联络人等。Greatfire推测,此次苹果受攻击,可能与香港占中的图像信息被分享到大陆有关。

用户要如何对抗此次攻击?

中国网民首先要在电脑和移动设备上使用可靠的浏览器:Firefox和Chrome在某网站遭中间人攻击时,都会阻止用户通向该网站。而奇虎360浏览器则没有安全防范,会直接打开受中间人攻击的网页。

如果用户忽略了安全提示,就应该使用不受干扰的方式来连接iCloud。用户可以通过VPN、或者不同的网络连接点,因为中国防火墙的中间人攻击并不稳定。用户还应该启用iCloud账户的两步认证法。这样,即使密码被盗取,iCloud账户也将受到保护。

Iphone加密系统升级惹恼中国?

最新的中间人攻击也可能与iPhone 6的安全措施升级有关。当新的苹果手机细节被公布之后,中国当局似乎不愿意新的iPhone在中国大陆发售。苹果为了防止NSA的窃听,升级了手机的加密功能。但这迫使中国当局无法窥视苹果用户的资料。iPhone 6可以正式在中国发售,不知苹果是否在中国改制了该手机的安全设置。但此次对iCloud的中间人攻击,似乎说明,中国当局与苹果在新手机的某些功能上有分歧。

苹果公司曾与中国当局有过一点暧昧的浪漫史,当中国当局要求苹果在其中国网店删除某些app时,苹果就范。因此,难以想象苹果高层对此次苹果受中国攻击有何感想。

此次攻击也给与积极配合中国审查要求的外国公司发出一个清晰的信号:协助当局审查网络并不能保证这些公司在中国财路通畅。相反,协助当局审查将被视为外国公司最糟糕的决定。不仅当局会反咬你一口,而且还将失去全球其他地方的客户。我们已要求苹果公司对此次攻击作出评论。

Technical evidence of attacks against iCloud.com (Apple) and login.live.com (Microsoft)

iCloud

The GFW (Great Firewall of China) is now wiretapping Apple’s iCloud. GFW implemented a MITM attack on iCloud using a self-signed certificate.

The authorities only attacked IP 23.59.94.46. Not all users in China are affected because the iCloud DNS might return different IP addresses.

Wirecapture with MITM: https://www.cloudshark.org/captures/03a6b0593436

Self-signed certificate used in the attack: http://www.mediafire.com/download/ampbnqncc277krv/fakeicloudcert.zip

Connection log: http://pastebin.com/tN7kbDV3

Traceroute:  http://pastebin.com/8Y6ZwfzG

Hotmail MITM

Wirecap: https://www.cloudshark.org/captures/6011389a8ea3

TCP Traceroute: https://twitter.com/siyanmao/status/518963824481681408

 

评论

更多博客文章

订阅 email
显示 博客 | Google+ | Twitter | 全部 的消息. 使用 RSS 订阅我们的博客。

星期一, 11月 25, 2024

China’s New Effort to Achieve Cyber Sovereignty

How Real-Name Registration policies create an “ideological firewall” that chills dissent by eliminating user anonymity and selectively restricting transnational access to Chinese social media apps.

星期四, 8月 10, 2023

1.4 million people used FreeBrowser to circumvent the Great Firewall of Turkmenistan

Since 2021, the authorities in Turkmenistan have taken exceptional measures to crack down on the use of circumvention tools. Citizens have been forced to swear on the Koran that they will not use a VPN. Circumvention tool websites have been systematically blocked. Arbitrary searches of mobile devices have also taken place and have even targeted school children and teachers.

The government has also blocked servers hosting VPNs which led to “near complete” internet shutdowns on several occasions in 2022. Current reports indicate that 66 hosting providers, 19 social networks and messaging platforms, and 10 leading content delivery networks (CDNs), are blocked in the country. The government presumably is unconcerned about the negative economic impact that such shutdowns can cause.

星期五, 3月 18, 2022

Well-intentioned decisions have just made it easier for Putin to control the Russian Internet

This article is in large part inspired by a recent article from Meduza (in Russian).

Since the beginning of the war in Ukraine, Russian users have had problems accessing government websites and online banking clients. Browsers began to mark these sites as unsafe and drop the connection. The reason is the revocation of digital security certificates by foreign certificate authorities (either as a direct consequence of sanctions or as an independent, good will move); without them, browsers do not trust sites and “protect” their users from them.

However, these actions, caused - or at least triggered by - a desire to punish Russia for their gruesome actions in Ukraine, will have long-lasting consequences for Russian netizens.

Digital certificates are needed to confirm that the site the user wants to visit is not fraudulent. The certificates contain encryption keys to establish a secure connection between the site and the user. It is very easy to understand whether a page on the Internet is protected by a certificate. One need just look at the address bar of the browser. If the address begins with the https:// prefix, and there is a lock symbol next to the address, the page is protected. By clicking on this lock, you can see the status of the connection, the name of the Certification Authority (CA) that issued the certificate, and its validity period.

There are several dozen commercial and non-commercial organizations in the world that have digital root certificates, but 3/4 of all certificates are issued by only five of the largest companies. Four of them are registered in the USA and one is registered in Belgium.

星期一, 8月 03, 2020

GreatFire 应用生成器 发布

GreatFire (https://en.greatfire.org/) 是一家专注于中国的审查监督组织,我们自豪地宣布一个新的反审查工具,该工具将使任何被屏蔽的媒体、博客、人权组织或民间社会组织反制审查,将其内容得以传播到中国和其他互联网审查国家的数百万读者和支持者的手机上。

GreatFire 已经构建了一个名为“GreatFire 应用生成器”的网页程序,任何组织可以使用它来为中国和其他国家的用户解锁他们的内容。任何人可以访问 (https://appmaker.greatfire.org/),该网站将编译一个带有自己logo的应用,并将包含他们以前被封锁的内容。该应用还将包含一个特殊的、绕过审查的网络浏览器,以便用户可以访问未经审查的网络。这些应用将使用包括机器学习在内的多种策略来规避中国当局先进的审查策略。这个项目在其他有类似中国的审查限制的国家也同样有效。对于组织和最终用户而言,这些应用将免费、快速且非常易于使用。

这个项目的灵感来自于GreatFire自己的应用 自由浏览(https://freebrowser.org/en)的第一手经验,并希望帮助那些可能没有内部专业知识来规避中国审查制度的小型非政府组织。GreatFire的反审查工具在中国发挥了作用,而其他工具却没有。自由浏览可以引导中国的互联网用户从应用的首页进入被僧所内容的导航(http://manyvoices.news/)。

   

人权基金会 (HRF) 已经使用 GreatFire 应用生成器 创建了一个应用程序HRF 在全球范围内促进和保护人权。该组织的使命是确保自由在世界范围内得到维护和促进。 HRF 的网站 在中国被封锁, 但现在中国任何人都可以 下载 HRF Android 应用程序 并访问该网站的信息。

“现在是中国政府防火墙倒塌的时候了,”人权基金会战略顾问王珍妮说。 “与我们在 GreatFire 的朋友一起,我们致力于击败中国的审查制度——在每一部手机。”

GreatFire 应用生成器 的起源可以追溯到 2014 年,当时开放技术基金 (OTF) 支持 GreatFire 的“依附的自由”实验。该项目直接导致了 2015 年中国政府的大规模网络攻击,后来被称为“大炮”。 OTF 还为 GreatFire 开发 AppleCensorship.com,该网站正在跟踪苹果对包括香港在内的全球应用商店的审查情况。

自由浏览 是“大炮”攻击的直接结果,五年后,我们很高兴能够向任何可能遭受中国当局审查的组织提供我们的方法。 

星期五, 7月 24, 2020

Apple, anticompetition, and censorship

On July 20, 2020, GreatFire wrote to all 13 members of the Subcommittee on Antitrust, Commercial and Administrative Law of the U.S. House Committee on the Judiciary, requesting a thorough examination into Apple’s practice of censorship of its App Store, and an investigation into how the company collaborates with the Chinese authorities to maintain its unique position as one of the few foreign tech companies operating profitably in the Chinese digital market.  

This letter was sent a week before Apple CEO TIm Cook will be called for questioning in front of the Subcommittee on Antitrust, Commercial and Administrative Law. The CEOs of Amazon, Google and Facebook will also be questioned on July 27, as part of the Committee’s ongoing investigation into competition in the digital marketplace.

This hearing offers an opportunity to detail to the Subcommittee how Apple uses its closed operating ecosystem to not only abuse its market position but also to deprive certain users, most notably those in China, of their right to download and use apps related to privacy, secure communication, and censorship circumvention.

We hope that U.S. House representatives agree with our view that Apple should not be allowed to do elsewhere what would be considered as unacceptable in the U.S. Chinese citizens are not second class citizens. Private companies such as Apple compromise themselves and their self-proclaimed values of freedom and privacy when they collaborate with the Chinese government and its censors.

使用 RSS 订阅我们的博客。

评论

uk.yahoo.com is also giving untrusted certificate warnings at this present time.

I'm surprised they've used self-signed. Surely they could have issued certs through cnnic (www.cnnic.cn). Most browsers trust their CA. You can test your browser by going to Https://Evdemo.cnnic.cn

@Anonymous: Because if they did that, cnnic would definitely not be trusted anymore...

Pretty creepy, they don't mind being as obvious as this...and this 360 browser accepts self-signed certificates by default? Wow.

On the other hand, can we rule out that it was an attack not connected to the Chinese government? Were all DNS servers in China affected? Why would they stop the attack this quick (icloud goes to the right IP for me now and I use my provider's DNS servers)? Not that I would not think that the government has hands in this, but I would not be surprised if it was a successful attack to a poorly secured big provider's DNS server (but then it wouldn't affect everybody in China...). Hmm when thinking about it, this poisoning must have been done through the GFW...any more detailed technical analysis available? Any official comments from CNNIC?

看我口型。操~~~他~~~妈~~~

Is the information obtained limited to iCloud users' data?

Is the information obtained limited to iCloud users' data?

inspired a lot from this post am following this blog regularly and found very good for bookmarking thanks admin
new year sms in hindi 2015
happy new year sms 2015
happy new year 2015 wallpapers
happy new year 2015 quotes
happy new year 2015
happy new year wishes 2015

This is really bad.Hope that steps will be taken in Year 2015 for better security.

Vry..Vry..Vry..Needful 4 my computer PPT....Thankxxx sooo much

Thanks a really nice post thanks for sharing.
[http://www.happyrepublicday-2015.com/ Republic Day 2015] Republic Day 2015
[http://www.happyrepublicday-2015.com/ Republic Day 2015] Republic Day 2015
[http://www.happyrepublicday-2015.com/ Republic Day 2015] Happy Republic Day 2015 SMS

McCoy does not shy from prevents and by most reports they
was a team participant with all the Eagles. and it has a huge amount of
has under his belt|it has a huge amount of carries under his belt and is 27 Your examination of the business and We agree generally, but the material about McCoyis
mindset and designed -the- problems is baloney.

Check out my web site: gift.ii-houyou.com (Jacob)

this post is awesome, great msg for us, plz update ur blog for daily basis, i am regular visitor of this site, so keep posting for us,

click the below links to create backlink
best free backlink website
click here for msg movie

Paragraph writing is also a fun, if you know
then you can write otherwise it is complicated to write.

My website How To Seo Html (Http://Support.Semanticmastery.Com/)

thanks for this post, keep it up for updating us, i am waiting for ur new article.
IPL8 live stream 2015
thanks again

Mind Blowing.. post great work

PC Games

Thanks Great Share.

Technology

LinkedIn decided to create a China-hosted version ?

Tech Blog

this is great information. article is ol;d but information is great
http://www.surveyremoveronline.com/

this is great information. article is ol;d but information is great
http://www.surveyremoveronline.com/

its time to grow up now for the best world and info you'll got.
Facebook Hacker

Exclusive release first on Internet Fifa 16 Crack arrived. Try the latest version of our fifa crack today and impress all of your friends with amazing highscores rankings - free of charge.

We have spent months developing this crack so that you can generate an unlimited amount of free Points, Coins.
http://fifacrack.com/

Republic Day 2016 Images

http://festivalsbag.com/

Republic Day 2016 Images
http://festivalsbag.com/

Republic Day 2016 Images
http://festivalsbag.com/

On the other hand, can we rule out that it was an attack not connected to the Chinese government? Were all DNS servers in China affected? Why would they stop the attack this quick (icloud goes to the right IP for me now and I use my provider's DNS servers)? Not that
would not think that the government has hands in this, but I would not be surprised if it was a successful attack to a poorly secured big provider's DNS server (but then it wouldn't affect everybody in China...). Hmm when thinking about it, this poisoning must have been done through the GFW...any more detailed technical analysis available? Any official comments from CNNIC http://www.sbnation.com/users/obatperangsang

is also giving untrusted certificate warnings at this present time. http://obatfrigid.com/obat-perangsang-pria.html

is also giving untrusted certificate warnings at this present time
http://toko-qta.com/

would not think that the government has hands in this, but I would not be surprised if it was a successful attack to a poorly secured big provider's DNS server (but then it wouldn't affect everybody in China...
http://tokovital.com/obat-perangsang-wanita.html

would not think that the government has hands in this, but I would not be surprised if it was a successful attack to a poorly
https://www.sbnation.com/users/perangsangwanita

Berita Terkini ElangNews.com http://www.elangnews.com/

Nonton bola online streaming http://nobartv.com

Komunitas fans bola indonesia http://soccerio.net

thank you very much for the article, hopefully by reading this article can add to my knowledge and experience and all friends who have read the content in this article http://www.obatpengikatwanita.com/

the application permits you making this examination on any kind of network, androdumpperr as well as run the installer data to comply with the setup directions.

Progression as it speeds with the DHL network. You'll Tracking to awaiting distributions that do not turn up as intended.

is also giving untrusted certificate warnings at this present time
http://www.tokomurah.id/

Progression as it speeds with the DHL network. You'll Tracking (http://www.tokomurah.id/obat-pelangsing-badan/) to awaiting distributions that do not turn up as intended.

Indeks berita bola terbaru hari ini pada NobarTV http://nobartv.com/index-berita/2018
Indeks jadwal streaming bola online hari ini di NobarTV http://nobartv.com/index-pertandingan/2018

Thank you for sharing the post. I didn't know that the Chinese authorities are now staging a man-in-the-middle (MITM) attack on Apple’s iCloud, Yooying where will they want to reach now, there were too many website and apps are blocked in China already.

添加新评论

Filtered HTML

  • 自动将网址与电子邮件地址转变为链接。
  • 允许的HTML标签:<a> <em> <strong> <cite> <blockquote> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • 自动断行和分段。

Plain text

  • 不允许HTML标记。
  • 自动将网址与电子邮件地址转变为链接。
  • 自动断行和分段。
By submitting this form, you accept the Mollom privacy policy.