Live data from Hacker News

GitHub under ongoing DDoS attack

status.github.com

11–20 of 352 posts

Re: GitHub under ongoing DDoS attack

#11
> 0:50 UTC - Into hour 71 defending the attack. Mitigation is holding and service is stable.

Wow, this has been going on for quite some time now!

> 8:18 UTC - The ongoing DDoS attack has changed tactics.

Someone knows more about this new tactics?

Re: GitHub under ongoing DDoS attack

#12
post #7

So.. Every website running baidu analytics is going to show a warning popup to all visitors, on every page?

That was an early issue, but - according to the GitHub status page - the attack has changed many times since that. Has anyone found any info. regarding what behaviour the attack is now exhibiting?

Re: GitHub under ongoing DDoS attack

#13
post #5

I'm confused - what is the reason behind it ?

Gizmodo has some info. but I wanted to find a less trashy source; the register has a story [1]. In short, it's suspected that the Chinese government is behind the attack because there are some projects hosted on GitHub that it ideologically disagrees with. [1] http://www.theregister.co.uk/2015/03/27/github_under_fire_fr...

Which raises the question: when will the rest of the world kick China of the internet? First it was redirecting Chinese internet users to random IPs, if the government didn't like their DNS queries and now they're doing ddos attack on a site that host a large percentage of open source code, used for a whole host of service and products.

At some point it's going to make more economical sense to kick China of the internet.

Re: GitHub under ongoing DDoS attack

#14
post #5

I'm confused - what is the reason behind it ?

Gizmodo has some info. but I wanted to find a less trashy source; the register has a story [1]. In short, it's suspected that the Chinese government is behind the attack because there are some projects hosted on GitHub that it ideologically disagrees with. [1] http://www.theregister.co.uk/2015/03/27/github_under_fire_fr...

They also have a pretty good weapon to aid them in this - their internet users.

They've been redirecting traffic of its user to load GitHub, which is a very smart/evil tactic to use - this is what certain sites did years ago to take down their smaller competitors.

Re: GitHub under ongoing DDoS attack

#16

Earlier quoted context omitted.

Gizmodo has some info. but I wanted to find a less trashy source; the register has a story [1]. In short, it's suspected that the Chinese government is behind the attack because there are some projects hosted on GitHub that it ideologically disagrees with. [1] http://www.theregister.co.uk/2015/03/27/github_under_fire_fr...

Which raises the question: when will the rest of the world kick China of the internet? First it was redirecting Chinese internet users to random IPs, if the government didn't like their DNS queries and now they're doing ddos attack on a site that host a large percentage of open source code, used for a whole host of service and products. At some point it's going to make more economical sense to kick China of the inter…

> Which raises the question: when will the rest of the world kick China of the internet?

Careful with that, because the moment some nation can kick out another nation out of the internet for whatever reason we're toasted.

Plus, it's better to wait and see some hard evidence (if any can be found) before jumping into conclusions.

Re: GitHub under ongoing DDoS attack

#17
post #5

I'm confused - what is the reason behind it ?

Gizmodo has some info. but I wanted to find a less trashy source; the register has a story [1]. In short, it's suspected that the Chinese government is behind the attack because there are some projects hosted on GitHub that it ideologically disagrees with. [1] http://www.theregister.co.uk/2015/03/27/github_under_fire_fr...

This speculative attribution seems a bit fishy to me.

This attack is a clumsy way to harass those projects. It's not sure to work, and is bringing the specific projects more attention in the meantime. As an official (or easily-attributable) extra-territorial action, it seems both unprecedented and disproportionate.

It's also drawing extra attention to the border machines and their capability to do man-in-the-middle tampering. I'd have thought CNGov would want to be miserly with that capability, to suppress awareness of the risk or development of countermeasures/workarounds.

I wouldn't completely rule out that this might be an action by some other party that intends, in a roundabout way, to raise an alarm about Chinese net borders.

Re: GitHub under ongoing DDoS attack

#20

Earlier quoted context omitted.

Gizmodo has some info. but I wanted to find a less trashy source; the register has a story [1]. In short, it's suspected that the Chinese government is behind the attack because there are some projects hosted on GitHub that it ideologically disagrees with. [1] http://www.theregister.co.uk/2015/03/27/github_under_fire_fr...

Which raises the question: when will the rest of the world kick China of the internet? First it was redirecting Chinese internet users to random IPs, if the government didn't like their DNS queries and now they're doing ddos attack on a site that host a large percentage of open source code, used for a whole host of service and products. At some point it's going to make more economical sense to kick China of the inter…

> > Which raises the question: when will the rest of the world kick China of the internet?

Well, that's exactly what the DDoS wanted, so the government could just happily control all access to Internet in mainland China

The DDoS targets github.com/greatfire and github.com/cn-nytimes by their so called "collateral freedom" [1]

Suppose github could just ban Chinese IP all together, but @greatfire could easily jump to another host and abuse ToS to hosting "neutral" political content, like bitbucket[2]

Many webmasters have already banned all Chinese IPs, so gradually, every public hosting service will eventually ban all Chinese IPs, Chinese government could easily destroy the rest of circumvention methods

[1]: https://en.greatfire.org/blog/2014/jan/collateral-freedom-fa...

[2] https://bitbucket.org/greatfire

Post reply on HN