Earlier quoted context omitted.
Its because the requests aren't actually coming from China. China is redirecting worldwide users from Baidu to GitHub. Sorry, I don't have the link handy, but it was in that WSJ article on the front page.
I do understand this, but if it's Chinese government behind attack the reason why they doing this it's these anti-censorship projects hosted on GitHub. Considering GitHub already supported censorship in Russia I see no reason why don't they just block access from China to projects that Chinese gov don't like.
GitHub under ongoing DDoS attack
271–280 of 352 posts
Re: GitHub under ongoing DDoS attack
#272Earlier quoted context omitted.
"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.
I don't think this qualifies as an act of war, not by a long shot. But that does raise an interesting question: what would be considered (or rather should) an act of war in cyberspace? Should the target be a whole nation? Or maybe enough of it to affect their ability to function? How much commerce disruption equates an act of war, even if no shots are fired? You'd need some pretty good proof and how would you respond…
I'm pretty sure blockading ports (as in cities where ships go, not network ports) counts, so that's a starting point. But on the other hand, blockades do tend to be backed up by at least threats of actual physical violence, so.... ?
Re: GitHub under ongoing DDoS attack
#273Earlier quoted context omitted.
Both are unethical, but there is a difference between spying (sitting with some binoculars by a window, or snooping around inside the building) and destructive actions (blowing up the entrance with a constant stream of TNT so no one else can get in). US does the former, China does both.
The US does damaging unethical things. https://news.ycombinator.com/item?id=9285146 They aren't just observing.
And though it's certainly not a great defense, the router bricking was unintentional.
The US generally does not engage in destructive actions with the intent of restricting the rights of their own citizens... just other country's citizens. China does both. Both are very bad, but I think the US still has a slight moral highground here.
Re: GitHub under ongoing DDoS attack
#274Earlier quoted context omitted.
That's not true at all, what the hell? Realize you're talking to folks who do this kind of stuff for a living, rather than just the random Internet denizens of most other websites. The FBI will regularly inform and assist companies who've been breached, for example. The US government is very interested in protecting US companies. That said, they don't quite have any guidance from congress on how to do that, so right…
When I was an admin of an IRC network we regularly reported large scale DDoS attacks to an FBI agent assigned to us. He didn't care. Some of those attacks took the network down for a while and resulted in many users moving to other networks. In at least two cases we even figured out the identity, address, and phone numbers of the people doing it and there was no movement on it. Then one day one of the people we had t…
Re: GitHub under ongoing DDoS attack
#275Earlier quoted context omitted.
Yes. The nature of git means this has not stopped our workflow. Just because we can't update a central source doesn't mean we can't continue to get things done. Also, if a large enough entity doesn't like what you're doing, you're better off putting your code in Github/Bitbucket/etc because chances are you can't mitigate a DDoS of this scale by yourself.
If you host your code on this "free" service and you cause a DDos because someone doesn't like what you are doing, are you going to pay for the mitigation costs to the free provider?
Re: GitHub under ongoing DDoS attack
#276Each time i hear about DDoS attacks i wonder why we don't have serious effective mitigation strategies even though there are brilliant computer scientists out there who always come up with very smart solutions, this is a genuine question and not a rhetorical one.
Most of it comes down to shoving 10X traffic down a 1X pipe. You can write smart fast software, but if your wires are saturated... There is one common problem, and that is that the major transit carriers/ISPs allow you to spoof your source IP. That allows some attacks to be done easier than otherwise. But that's more of a special case and doesn't matter when there is hijacking going on like in this attack. Blocking a…
Re: GitHub under ongoing DDoS attack
#277Earlier quoted context omitted.
"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.
We should never take up arms for a thread that has no human casualties, especially when there are alternatives. If your neighbour enter your home uninvited, because the door is not locked, the first thing you do is ask nicely not to do that. The next thing you do is lock the door. You don't start shooting at them first ...
Re: GitHub under ongoing DDoS attack
#278Earlier quoted context omitted.
I assumed it was implied.
As a non-paying customer I have seen nothing but 100% uptime and perfect service. If it weren't for HN and Twitter I wouldn't even know Github was under attack.
At least I've seen a few "connection refused"/"timeout" error notifications from one of the sites I manage. Don't know the successful login counts, so no idea how high the error rate is.
Re: GitHub under ongoing DDoS attack
#279Earlier quoted context omitted.
We should never take up arms for a thread that has no human casualties, especially when there are alternatives. If your neighbour enter your home uninvited, because the door is not locked, the first thing you do is ask nicely not to do that. The next thing you do is lock the door. You don't start shooting at them first ...
I'd say cut the internet trunk lines to China... period.. end of story. That would seem to be an appropriate response. Blacklist China's internet traffic completely.
Re: GitHub under ongoing DDoS attack
#280Earlier quoted context omitted.
We should never take up arms for a thread that has no human casualties, especially when there are alternatives. If your neighbour enter your home uninvited, because the door is not locked, the first thing you do is ask nicely not to do that. The next thing you do is lock the door. You don't start shooting at them first ...
This wouldn't be the first time China has hacked US-based organizations.