Live data from Hacker News

GitHub under ongoing DDoS attack

status.github.com

251–260 of 352 posts

Re: GitHub under ongoing DDoS attack

#251
post #130
post #21

As a paying customer of Github I want them to know they have my undivided support in staying strong against "the bullies".

"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.

I don't think this qualifies as an act of war, not by a long shot. But that does raise an interesting question: what would be considered (or rather should) an act of war in cyberspace?

Should the target be a whole nation? Or maybe enough of it to affect their ability to function? How much commerce disruption equates an act of war, even if no shots are fired?

You'd need some pretty good proof and how would you respond? With another cyber attack? Or escalate into a shooting war? Or by disconnecting the attacking country from the internet?

Re: GitHub under ongoing DDoS attack

#252
post #130

Earlier quoted context omitted.

"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.

It's become clear to me over the past 5-10 years or so that we're in some sort of weird undeclared war on the Internet. Nations are doing exactly what you describe, and it seems there is little to no repercussions for them doing so.

A long cold cyberwar http://www.flourish.org/2015/01/long-cold-cyberwar/

Re: GitHub under ongoing DDoS attack

#253
post #130

Earlier quoted context omitted.

"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.

We should never take up arms for a thread that has no human casualties, especially when there are alternatives. If your neighbour enter your home uninvited, because the door is not locked, the first thing you do is ask nicely not to do that. The next thing you do is lock the door. You don't start shooting at them first ...

Except in Texas ;)

I wouldn't be averse to depth charging a fiber optic cable (more specifically - damaging their ability to operate the great firewall) so long as there are no human casualties. Even better if it could be done without disrupting Chinese Internet.

Unfortunately, most people's response would be "What's a GitHub"?

Re: GitHub under ongoing DDoS attack

#254
post #243

Gitchain needed please, if we can stop ignoring the root of the problem is the habit to preserve corporal central force. http://Gitchain.org links with http://Factom.org and needs complement not ignore the deep research and development environment we need to profoundly edit safed social structure. (Their author failed to secure funding for Gitchain and then made Factom, while the issue needs equally relate each part…

Was that markov text?

Reading is painful? Reading painful? Reading too painful to count?

(Pain even if it matters the odd variables are resistance to and war away from sharing and hosting collective change logs?)

Re: GitHub under ongoing DDoS attack

#255
post #153

Hi, foreigner working in Chinese high tech company here. I wonder a bit, on which ground is this attack attributed to Chinese gov? It looks a bit unlikely to me. China has some cyber military but they are more likely to be pragmatic and choose wisely their targets. There's a bunch of script kiddies but they would choose also something else. However it seems possible that many servers hosted in China are not secured a…

> China has some cyber military... China has approximately 2 million people in its 'cyber army'. Not all of them are going to be experts, but sheer volume makes them probably the most effective 'cyber army' out there.

If that's true (which I don't know) then just directing those people manually visiting websites would bring quite a few targets to their knees, some basic automation and you have a real problem.

Re: GitHub under ongoing DDoS attack

#256
post #5

I'm confused - what is the reason behind it ?

My view - based on no evidence, just reasoning from what we know - is that China are scared of Github.

They can't shut it down fully, because doing so would shut down their software engineering capability (it has got that important). And people can host basically anything there, including anti-censorship software.

Attack feels like a power play to me. Either to pressurise Github into censoring for the PRC - "block the repos we hate, or we DOS your whole service again".

And/or to build a local competitor. The more Github is down, the more it is considered "anti-China" in China, the easier to build a local competitor.

This is all just my immediate hypothesis from the news. I'd love to see somebody who knows more about software development in China to say what might be really going on.

Re: GitHub under ongoing DDoS attack

#257
post #241
post #130

Earlier quoted context omitted.

"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.

I hope that by "full support of federal law enforcement, if not the military" you mean whatever cyber defense and possibly offense forces they have. I really hope that nobody thinks this is worth starting a shooting war with a rival nuclear superpower over.

PRC is not (yet) a superpower.

Re: GitHub under ongoing DDoS attack

#258

From looking at the Javascript injection code ( http://www.theregister.co.uk/2015/03/27/github_under_fire_fr... ) it seems like the quality of the script is pretty amateur. They inject jQuery not once, but twice, and only use jQuery to make a simple XHR request. Perhaps they are worried about one instance of jQuery being taken down or made unavailable to them, but they really don't need jQuery at all for something th…

I love that even PRC's DDoS attacks on U.S. technology resources invoke jQuery twice.

Re: GitHub under ongoing DDoS attack

#259
post #130
post #21

As a paying customer of Github I want them to know they have my undivided support in staying strong against "the bullies".

"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.

> We don't allow foreign raiding parties to enter our country to loot private businesses.

Really? The US government does just that, by mass spying of telecommunications.

Re: GitHub under ongoing DDoS attack

#260
post #127

Earlier quoted context omitted.

I assumed it was implied.

As a non-paying customer I have seen nothing but 100% uptime and perfect service. If it weren't for HN and Twitter I wouldn't even know Github was under attack.

Seriously, I had one page hang for about a second before responding, and honestly thought that was just my crappy wifi card(and may very well be).
Post reply on HN