Live data from Hacker News

GitHub under ongoing DDoS attack

status.github.com

151–160 of 352 posts

Re: GitHub under ongoing DDoS attack

#151
post #130

Earlier quoted context omitted.

"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.

It's become clear to me over the past 5-10 years or so that we're in some sort of weird undeclared war on the Internet. Nations are doing exactly what you describe, and it seems there is little to no repercussions for them doing so.

I agree...it seems much more akin to sport than militaristic action.

Since sport is pretty much a direct offshoot of war, I think the analogy works ok.

Re: GitHub under ongoing DDoS attack

#153
Hi, foreigner working in Chinese high tech company here. I wonder a bit, on which ground is this attack attributed to Chinese gov? It looks a bit unlikely to me. China has some cyber military but they are more likely to be pragmatic and choose wisely their targets. There's a bunch of script kiddies but they would choose also something else. However it seems possible that many servers hosted in China are not secured and could be used for this attack, by some other people.

Just my first thought as an insider...

Re: GitHub under ongoing DDoS attack

#154
post #153

Hi, foreigner working in Chinese high tech company here. I wonder a bit, on which ground is this attack attributed to Chinese gov? It looks a bit unlikely to me. China has some cyber military but they are more likely to be pragmatic and choose wisely their targets. There's a bunch of script kiddies but they would choose also something else. However it seems possible that many servers hosted in China are not secured a…

The MITM on HTTPS traffic that seems to be involved in the first attack stages is actually pretty good evidence.

Re: GitHub under ongoing DDoS attack

#155

Classic amateur hour over at GitHub. Another reminder that you may know how to hack, but you're no computer expert. It would be best to call for help than continue this charade GitHub. You failed.

Are you saying that GitHub have failed?

Could you explain why? Have you not been able to commit/push/pull/browser github because of the attack?

Re: GitHub under ongoing DDoS attack

#156
post #95

Earlier quoted context omitted.

I doubt the Chinese government is behind the attack - except for maybe not caring enough to do anything about it. Basically the government doesn't really care what other people do outside the Chinese Internet, and just block anything they don't want local people to read. Far more likely is a 'red hacker', e.g. Someone hacking for patriotic reasons and has taken issue with those projects hosted on GitHub. It may well…

Your comment is flatly wrong. 完全不对。 I've lived in and researched China for 28 years.

It's not flatly wrong.

I might not have lived in and researched China for 28 years, but I'm not exactly a stranger to the place and have spent the better part of a decade in China and the greater China area and have been circumventing the great firewall for almost 15 years.

Unless your China research has been limited to something like the tea cultivating habits of the Bulang minority, you should be able to list off the top of your head a half dozen better targets than the current attack, which is two relatively small projects, largely unknown to the Chinese people, and hosted on another website (GitHub) that is once again largely unknown to majority of Chinese Internet users.

I still stand by my statement that the Chinese government doesn't really care what the rest of the world reads/watches so long as they can control what their local citizens have access too.

If the Chinese government wanted those projects gone they would just block those project pages. Their current infrastructure is more than sufficient to do that both from a technical perspective in blocking just those projects rather than the entire GitHub domain, and from a man power perspective (tens of thousands of people employed to monitor the web for 'objectionable' content).

If the government was really interested in knocking material they find objectionable off the internet through a DDoS then thanks to the GFW they already have a big list of sites and content they don't like and they could take the total GitHub DDoS traffic and proportion it among the top however many sites they don't like and bring them down far more easily than bringing down GitHub, and with far less people caring about it.

P.S. If you want me to take you seriously as an expert on China, you probably shouldn't put google-translated Chinese messages on your twitter feed.

Re: GitHub under ongoing DDoS attack

#158
post #144

Can Github ask for US Government help with it, since it's an attack by [presumably] foreign sovereign entity? It's paying taxes in US, right — so it may expect some kind of protection, isn't this what taxes are about?

""Cybercrime"" and ""cyberterrorism"" resources are only deployed (a) for securing more funding (b) for expanding US surveillance or sometimes (c) on behalf of big donors like the copyright industry. The US has no interest in saying "international cyberattack should be illegal" because then other countries might insist that it stop. They could go for a trade war escalation, but that would at some point have Apple as…

That's not true at all, what the hell?

Realize you're talking to folks who do this kind of stuff for a living, rather than just the random Internet denizens of most other websites.

The FBI will regularly inform and assist companies who've been breached, for example. The US government is very interested in protecting US companies.

That said, they don't quite have any guidance from congress on how to do that, so right now the assistance is limited. It is most certainly there, however, and your tinfoil-hat nonsense doesn't really fly.

Re: GitHub under ongoing DDoS attack

#159

Earlier quoted context omitted.

I don't think banning countries from the Internet is the answer, but net neutrality seems like a completely separate issue.

Net neutrality is about carriers treating all traffic equally. Banning a country from the internet is discriminating traffic by origin. That sounds like a net neutrality issue if there ever was one. Whether the discrimination happens in the hardware or in the software stack is a mere implementation detail.

Sure it is, but if some carriers are a state-sponsored arm of a bad actor and are told by their masters not to treat traffic equally, thus breaking the net neutrality pact, then what are the responsibilities of the the other carriers?

Worms, meet can.

Re: GitHub under ongoing DDoS attack

#160
post #153

Hi, foreigner working in Chinese high tech company here. I wonder a bit, on which ground is this attack attributed to Chinese gov? It looks a bit unlikely to me. China has some cyber military but they are more likely to be pragmatic and choose wisely their targets. There's a bunch of script kiddies but they would choose also something else. However it seems possible that many servers hosted in China are not secured a…

This might be part of the attribution:

https://news.ycombinator.com/item?id=9275381

Post reply on HN