Live data from Hacker News

GitHub is getting DDoSed again

status.github.com

21–30 of 75 posts

Re: GitHub is getting DDoSed again

#21
post #6

This happened back in October a couple of days in a row. Who the heck is targeting Github and why? I wonder if these attacks are related to the Chinese hacking attacks that have been publicised lately?

Hm, I don't think it fits the pattern. The most reported Chinese hacking was about espionage, not bringing down websites. Most of the time, DDOS is either related to politics (newspapers, federal agencies etc.) or related to blackmailing (most likely in the case of GitHub. This of course, does not mean that the hacker is NOT sitting in China. But she could be placed everywhere else just as likely.

A lot of Chinese (and everyone else) hacking has been for good old fashion profit. But I do agree, I doubt the Chinese or any other "criminal" element is behind this attack.

Github either pissed someone off, or it's about "street cred".

I was interviewing a candidate about a year ago. Who bragged to me that he hacked the North Broward Hospital District.

And I was like, "why would you hack a hospital?"

His answer, "It was there."

I was dumb-founded. I mean I hired him, but still. :)

Re: GitHub is getting DDoSed again

#22
If several countries, distribute across various continents, have managed to put in place three-strikes and six-strikes (not that I think it's good), it means that the one and foremost knee-jerking argument saying "You can't do anything about DDoS because: [X] It's technically not realist" is gone.

Technically now ISPs could throttle the bandwith (or even disallow net access) to zombies boxen used in DDoS attacks in all the countries applying "x-strikes" rules.

So there may be light at the end of the tunnel.

It's not exactly as if DDoS was a fatality and nothing could be done about it.

Re: GitHub is getting DDoSed again

#23
post #10
post #5

This is a pretty typical occurrence for a web service provider of their size. When is Github going to be able to not fail when targeted?

Questions in case of Github remain: Who and why Its not like DDoSing a target of this size is totally 'free'.

We should first now the size of the attack and how many zombies are participating.

With all the exploits out there coming out on a nearly daily basis it's not exactly either as if having an army of a few tens of thousands of zombies was expensive...

Re: GitHub is getting DDoSed again

#24

This happened back in October a couple of days in a row. Who the heck is targeting Github and why? I wonder if these attacks are related to the Chinese hacking attacks that have been publicised lately?

I often have to wonder if the DDoS gods roll a dice and pick someone to screw each day. We have had many DDoS attacks and never once had any indication as to why. A few days ago we had a 30 Gbit DDoS. Our server host just blackholed any IP that was touched by it. They kept moving it around to target different bits of our infrastructure (unlike previous attacks that just targeted our website). We lost 6 servers, but t…

If your nickname here can somehow be linked to the company you're working for (e.g. by checking previous messages you posted to HN or on another board) I think it's not very smart to write what you just wrote.

Now the bad guys knows that they should just have tried a bit longer.

Now maybe that because you were DROP'ing / blacklisting IPs maybe they just ran out of zombies but still...

If I was the attacker and read your message and wanted to be bad, I'd just hammer you a bit more to put you in trouble.

Besides that there are some ISPs who do care about both keeping you online and fighting the low-life scums: the ISP XS4ALL from the Netherlands is (was at least) notoriously famous for that.

Re: GitHub is getting DDoSed again

#25

This happened back in October a couple of days in a row. Who the heck is targeting Github and why? I wonder if these attacks are related to the Chinese hacking attacks that have been publicised lately?

> wonder if these attacks are related to the Chinese hacking attacks that have been publicised lately?

Might be just me, but I don't like this trend. I'm seeing "the chinese" & "hacking" used too much together without proof more often than not. Almost as if they are being made into the next boogeyman to be afraid of.

Re: GitHub is getting DDoSed again

#26

This happened back in October a couple of days in a row. Who the heck is targeting Github and why? I wonder if these attacks are related to the Chinese hacking attacks that have been publicised lately?

I often have to wonder if the DDoS gods roll a dice and pick someone to screw each day. We have had many DDoS attacks and never once had any indication as to why. A few days ago we had a 30 Gbit DDoS. Our server host just blackholed any IP that was touched by it. They kept moving it around to target different bits of our infrastructure (unlike previous attacks that just targeted our website). We lost 6 servers, but t…

Get a smaller host, that way they can't afford to cut you of.

Re: GitHub is getting DDoSed again

#27
post #21
post #6

Earlier quoted context omitted.

Hm, I don't think it fits the pattern. The most reported Chinese hacking was about espionage, not bringing down websites. Most of the time, DDOS is either related to politics (newspapers, federal agencies etc.) or related to blackmailing (most likely in the case of GitHub. This of course, does not mean that the hacker is NOT sitting in China. But she could be placed everywhere else just as likely.

A lot of Chinese (and everyone else) hacking has been for good old fashion profit. But I do agree, I doubt the Chinese or any other "criminal" element is behind this attack. Github either pissed someone off, or it's about "street cred". I was interviewing a candidate about a year ago. Who bragged to me that he hacked the North Broward Hospital District. And I was like, "why would you hack a hospital?" His answer, "It…

It's a Monty Python sort of joke?

Interviewer: (sings) Good night, ring-ding-dingy. (shouts) Five, four, three, two, one!

Candidate: (cackles like a chicken)

Interviewer: (writing) Good! Very good, indeed!

Re: GitHub is getting DDoSed again

#28
post #16

I think GitHub should add hardcore anti-scraping functionality. Even though I enjoy Opensource repositories, I wouldn't like some bot/govermnent or other evil to mess with all of our contributions to humanity in a way to defeat us.

If it's open, I can scrape it.
Post reply on HN