Live data from Hacker News

GitHub under ongoing DDoS attack

status.github.com

181–190 of 352 posts

Re: GitHub under ongoing DDoS attack

#181
post #168

Earlier quoted context omitted.

This might be part of the attribution: https://news.ycombinator.com/item?id=9275381

Thanks, so if I understand well, every js gotten from baidu cdn from outside China has a malicious code attacking github. Weird. It could be some test gone wrong, but I still don't buy Chinese gov attacking purposely and openly github like that. It's like showing your one time secret weapon way too early and on some wrong target. Or maybe it's a way to make some big noise to the left while the real target is discrete…

There's no secret weapon, and how do you know it's the "wrong" target?

Re: GitHub under ongoing DDoS attack

#182
post #70
post #58

Out of curiosity, would Cloudflare be able to sustain the amount of inbound requests they're handling?

Haven't seen many stats, but I'm pretty sure they could. If I remember correctly they deflected one of the largest we've ever seen which even made trouble for the Internet's infrastructure.

This [1] is what you're referring to, I believe.

[1] https://www.youtube.com/watch?v=w04ZAXftQ_Y

Re: GitHub under ongoing DDoS attack

#183
The attack is an act supported by Chinese Government. it is an battle between a autarchic country and an company. China is good at it, a few days ago, Google issues Warning on Rogue Chinese Digital TLS Certs.

The best response to the attack is to sell and not buy stocks of Chinese IT companies and not using any of their products.

Here are some companies who work for GFW: venustech(启明星辰) Qihoo(NYSE: QIHU) 360.cn(360安全卫士)

They don't care about how you feel but They DO and ONLY care about their money.

China is military dictatorship. It is actually a Developed ISIS country.

Here are some pics to help you understand China. https://pbs.twimg.com/media/CAe6HhaXIAAfyll.jpg https://pbs.twimg.com/media/B_phuEKU0AAoa0r.jpg https://pbs.twimg.com/media/B3clncbCAAALgED.jpg

Re: GitHub under ongoing DDoS attack

#184
post #173

Each time i hear about DDoS attacks i wonder why we don't have serious effective mitigation strategies even though there are brilliant computer scientists out there who always come up with very smart solutions, this is a genuine question and not a rhetorical one.

I think the main difficulty is how to determine whether traffic is legitimate or not. Banning ranges of IP addresses is effectively denying service to non-attackers as well, so they win. The game is to soften their traffic's load on your system as much as possible while keeping things available.

Re: GitHub under ongoing DDoS attack

#187
post #168

Earlier quoted context omitted.

This might be part of the attribution: https://news.ycombinator.com/item?id=9275381

Thanks, so if I understand well, every js gotten from baidu cdn from outside China has a malicious code attacking github. Weird. It could be some test gone wrong, but I still don't buy Chinese gov attacking purposely and openly github like that. It's like showing your one time secret weapon way too early and on some wrong target. Or maybe it's a way to make some big noise to the left while the real target is discrete…

I agree it seems to be a stupid move for a government, and maybe someone else has gained access to the right routers. But "some test gone wrong"? You can't be serious. This is a carefully targeted attack and includes packets that can't be generated from a web browser.

Re: GitHub under ongoing DDoS attack

#189
post #168

Earlier quoted context omitted.

This might be part of the attribution: https://news.ycombinator.com/item?id=9275381

Thanks, so if I understand well, every js gotten from baidu cdn from outside China has a malicious code attacking github. Weird. It could be some test gone wrong, but I still don't buy Chinese gov attacking purposely and openly github like that. It's like showing your one time secret weapon way too early and on some wrong target. Or maybe it's a way to make some big noise to the left while the real target is discrete…

> Weird. It could be some test gone wrong, but I still don't buy Chinese gov attacking purposely and openly github like that.

A "test" that specifically targets two projects that promote anti-censorship. Yeah, that's some "test"...

Re: GitHub under ongoing DDoS attack

#190
post #144

Can Github ask for US Government help with it, since it's an attack by [presumably] foreign sovereign entity? It's paying taxes in US, right — so it may expect some kind of protection, isn't this what taxes are about?

""Cybercrime"" and ""cyberterrorism"" resources are only deployed (a) for securing more funding (b) for expanding US surveillance or sometimes (c) on behalf of big donors like the copyright industry. The US has no interest in saying "international cyberattack should be illegal" because then other countries might insist that it stop. They could go for a trade war escalation, but that would at some point have Apple as…

Please don't write such baseless assertions; we are trying to keep the post quality high here.

Your other responder works in this field, and I have been on the other side (worked for a company that got this sort of help). We also regularly had the FBI come in and give talks on the sorts of things they were working on in this space.

Post reply on HN