Live data from Hacker News

GitHub under ongoing DDoS attack

status.github.com

271–280 of 352 posts

Re: GitHub under ongoing DDoS attack

#271
post #200
post #194

Earlier quoted context omitted.

Its because the requests aren't actually coming from China. China is redirecting worldwide users from Baidu to GitHub. Sorry, I don't have the link handy, but it was in that WSJ article on the front page.

I do understand this, but if it's Chinese government behind attack the reason why they doing this it's these anti-censorship projects hosted on GitHub. Considering GitHub already supported censorship in Russia I see no reason why don't they just block access from China to projects that Chinese gov don't like.

Because Github does not want to be complicit in Chinese government censorship, and if they blocked what that government obviously wants them to block, then they would be.

Re: GitHub under ongoing DDoS attack

#272
post #130

Earlier quoted context omitted.

"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.

I don't think this qualifies as an act of war, not by a long shot. But that does raise an interesting question: what would be considered (or rather should) an act of war in cyberspace? Should the target be a whole nation? Or maybe enough of it to affect their ability to function? How much commerce disruption equates an act of war, even if no shots are fired? You'd need some pretty good proof and how would you respond…

How much commerce disruption equates an act of war, even if no shots are fired?

I'm pretty sure blockading ports (as in cities where ships go, not network ports) counts, so that's a starting point. But on the other hand, blockades do tend to be backed up by at least threats of actual physical violence, so.... ?

Re: GitHub under ongoing DDoS attack

#273
post #269

Earlier quoted context omitted.

Both are unethical, but there is a difference between spying (sitting with some binoculars by a window, or snooping around inside the building) and destructive actions (blowing up the entrance with a constant stream of TNT so no one else can get in). US does the former, China does both.

The US does damaging unethical things. https://news.ycombinator.com/item?id=9285146 They aren't just observing.

They do, but usually those actions are done against "belligerent" entities.

And though it's certainly not a great defense, the router bricking was unintentional.

The US generally does not engage in destructive actions with the intent of restricting the rights of their own citizens... just other country's citizens. China does both. Both are very bad, but I think the US still has a slight moral highground here.

Re: GitHub under ongoing DDoS attack

#274
post #229

Earlier quoted context omitted.

That's not true at all, what the hell? Realize you're talking to folks who do this kind of stuff for a living, rather than just the random Internet denizens of most other websites. The FBI will regularly inform and assist companies who've been breached, for example. The US government is very interested in protecting US companies. That said, they don't quite have any guidance from congress on how to do that, so right…

When I was an admin of an IRC network we regularly reported large scale DDoS attacks to an FBI agent assigned to us. He didn't care. Some of those attacks took the network down for a while and resulted in many users moving to other networks. In at least two cases we even figured out the identity, address, and phone numbers of the people doing it and there was no movement on it. Then one day one of the people we had t…

Its a matter of finance more than anything - if the people of the United States are paying you to protect national interests that is exactly what they should be doing. I can't speak for your specific situation but my time on the internet leads me to believe they have bigger fish to fry. Sorry though man I know that had to suck.

Re: GitHub under ongoing DDoS attack

#275
post #203

Earlier quoted context omitted.

Yes. The nature of git means this has not stopped our workflow. Just because we can't update a central source doesn't mean we can't continue to get things done. Also, if a large enough entity doesn't like what you're doing, you're better off putting your code in Github/Bitbucket/etc because chances are you can't mitigate a DDoS of this scale by yourself.

If you host your code on this "free" service and you cause a DDos because someone doesn't like what you are doing, are you going to pay for the mitigation costs to the free provider?

Why would I? That someone should pay. What you seem to suggest is DDoS victim blaming :P

Re: GitHub under ongoing DDoS attack

#276
post #173

Each time i hear about DDoS attacks i wonder why we don't have serious effective mitigation strategies even though there are brilliant computer scientists out there who always come up with very smart solutions, this is a genuine question and not a rhetorical one.

Most of it comes down to shoving 10X traffic down a 1X pipe. You can write smart fast software, but if your wires are saturated... There is one common problem, and that is that the major transit carriers/ISPs allow you to spoof your source IP. That allows some attacks to be done easier than otherwise. But that's more of a special case and doesn't matter when there is hijacking going on like in this attack. Blocking a…

If it were possible to stop some of that 10X before it even got to the pipe, would be the only kind of mitigation for that kind of attack. For something like that though, would require some pretty sophisticated firewall technology that lives outside of your infrastructure.

Re: GitHub under ongoing DDoS attack

#277
post #130

Earlier quoted context omitted.

"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.

We should never take up arms for a thread that has no human casualties, especially when there are alternatives. If your neighbour enter your home uninvited, because the door is not locked, the first thing you do is ask nicely not to do that. The next thing you do is lock the door. You don't start shooting at them first ...

I'd say cut the internet trunk lines to China... period.. end of story. That would seem to be an appropriate response. Blacklist China's internet traffic completely.

Re: GitHub under ongoing DDoS attack

#278
post #127

Earlier quoted context omitted.

I assumed it was implied.

As a non-paying customer I have seen nothing but 100% uptime and perfect service. If it weren't for HN and Twitter I wouldn't even know Github was under attack.

OAuth seem to have sporadic issues, which, I guess, may cause failures to "Log in with Github" auth on some occasions.

At least I've seen a few "connection refused"/"timeout" error notifications from one of the sites I manage. Don't know the successful login counts, so no idea how high the error rate is.

Re: GitHub under ongoing DDoS attack

#279

Earlier quoted context omitted.

We should never take up arms for a thread that has no human casualties, especially when there are alternatives. If your neighbour enter your home uninvited, because the door is not locked, the first thing you do is ask nicely not to do that. The next thing you do is lock the door. You don't start shooting at them first ...

I'd say cut the internet trunk lines to China... period.. end of story. That would seem to be an appropriate response. Blacklist China's internet traffic completely.

Cut off internet contact with the country that holds a ton of US debt, and manufactures all the little doo-dads we all use in our day-to-day lives?

Re: GitHub under ongoing DDoS attack

#280

Earlier quoted context omitted.

We should never take up arms for a thread that has no human casualties, especially when there are alternatives. If your neighbour enter your home uninvited, because the door is not locked, the first thing you do is ask nicely not to do that. The next thing you do is lock the door. You don't start shooting at them first ...

This wouldn't be the first time China has hacked US-based organizations.

Do you think the reverse isn't happening?
Post reply on HN