Live data from Hacker News

GitHub under ongoing DDoS attack

status.github.com

91–100 of 352 posts

Re: GitHub under ongoing DDoS attack

#91

Earlier quoted context omitted.

Any company that makes most or all of its money online is the subject of DDoS attacks for blackmail purposes, github a bit more so because the Chinese government doesn't like it. It's unfortunately a very normal thing these days.

What is the PRC's problem with Github?

They host the 'GreatFire' org and other software to bypass their censorship firewall.

Re: GitHub under ongoing DDoS attack

#92

Earlier quoted context omitted.

Any company that makes most or all of its money online is the subject of DDoS attacks for blackmail purposes, github a bit more so because the Chinese government doesn't like it. It's unfortunately a very normal thing these days.

What is the PRC's problem with Github?

Probably because Github is hosting code they don't like (e.g. code used to bypass censorship).

Re: GitHub under ongoing DDoS attack

#94

Earlier quoted context omitted.

Any company that makes most or all of its money online is the subject of DDoS attacks for blackmail purposes, github a bit more so because the Chinese government doesn't like it. It's unfortunately a very normal thing these days.

What is the PRC's problem with Github?

Its due to these two repost most likely.

https://github.com/greatfire/

https://github.com/cn-nytimes/

Access to them is currently no possible though.

Re: GitHub under ongoing DDoS attack

#95
post #5

I'm confused - what is the reason behind it ?

Gizmodo has some info. but I wanted to find a less trashy source; the register has a story [1]. In short, it's suspected that the Chinese government is behind the attack because there are some projects hosted on GitHub that it ideologically disagrees with. [1] http://www.theregister.co.uk/2015/03/27/github_under_fire_fr...

I doubt the Chinese government is behind the attack - except for maybe not caring enough to do anything about it.

Basically the government doesn't really care what other people do outside the Chinese Internet, and just block anything they don't want local people to read.

Far more likely is a 'red hacker', e.g. Someone hacking for patriotic reasons and has taken issue with those projects hosted on GitHub.

It may well be that the person has government connections or works in some way for the government but I'd be surprised if it was a government sponsored/sanctioned attack - especially because there are far more likely candidates who will be far easier to take offline than GitHub.

The Chinese government's strategy has generally been about keeping things out, not taking things down.

Re: GitHub under ongoing DDoS attack

#96
post #79

Earlier quoted context omitted.

You can serve an X-Frame-Options:"DENY" (or "SAMEORIGIN") header to prevent browsers from loading the iframes.

But this is a response header, so server shoud respond and that is the goal of attack. Browser doesn't send any request headers saying that site is opened in the iframe.

Sure, but at least the browser won't render the page, so it won't download the additional content like images and scripts. It's partial mitigation.

Re: GitHub under ongoing DDoS attack

#98

Earlier quoted context omitted.

I really wish they would post what the attacker wants removed so we could mirror it, post it, etc. The streisand effect is a good response to things like this I think.

It appears that the first attack was targeted at https://github.com/cn-nytimes/ and https://github.com/greatfire/ [1]. Accessing these two pages still responds with `alert("WARNING: malicious javascript detected on this domain")` which is supposed to be executed on the (innocent) client's browser. [1] https://news.ycombinator.com/item?id=9275381

You can access those pages by removing the final slash.

Re: GitHub under ongoing DDoS attack

#99
post #94

Earlier quoted context omitted.

What is the PRC's problem with Github?

Its due to these two repost most likely. https://github.com/greatfire/ https://github.com/cn-nytimes/ Access to them is currently no possible though.

It is:

https://github.com/cn-nytimes

https://github.com/greatfire

Re: GitHub under ongoing DDoS attack

#100

Earlier quoted context omitted.

Gizmodo has some info. but I wanted to find a less trashy source; the register has a story [1]. In short, it's suspected that the Chinese government is behind the attack because there are some projects hosted on GitHub that it ideologically disagrees with. [1] http://www.theregister.co.uk/2015/03/27/github_under_fire_fr...

Which raises the question: when will the rest of the world kick China of the internet? First it was redirecting Chinese internet users to random IPs, if the government didn't like their DNS queries and now they're doing ddos attack on a site that host a large percentage of open source code, used for a whole host of service and products. At some point it's going to make more economical sense to kick China of the inter…

China will be kicked from the internet at about the same time US and their NSA will be kicked.

Which is quite unlikely. We don't kick out USA because NSA breaks into backbone routers, steal encryption codes from sim cards, and steal traffic from google search, Gmail and Facebook. China attacks github, and the reaction will be likely the same.

At some point, it is going to make a economical sense to issue a treaty against this kind of behaviors. A treaty that forbids attacking fellow nations infrastructure and businesses over the Internet will benefit everyone, and it is going to take a long time before it is commonly understood.

Post reply on HN