Live data from Hacker News

GitHub under ongoing DDoS attack

status.github.com

301–310 of 352 posts

Re: GitHub under ongoing DDoS attack

#302

Earlier quoted context omitted.

You aren't going to make ddos attacks go away by offering prizes for a miracle software solution. It amazes me that there are so many programmers here who don't understand this basic principal. I think the only way we can get people to understand the situation is with an analogy. Let's say your pipe can receive 1 Liter per second of water. There are some impurities that you can filter through your faucet, this is ana…

I think there are plenty of people, myself included, who understand how DDoS attacks work. Do you know how X-Prizes work? Hit: Did I say anything about software? [edit: It's odd to me that this would get down voted. Is it offensive? Or are downvoters really that opposed to thinking outside of the box? The X-Prize encourages participation from unexpected directions, precisely where innovation is often found. As the pa…

>Did I say anything about software?

Well, you did say:

"Who'd like to sponsor? Or should I just spin up a GitHub repo for the code and a kickstarter for the prize money?"

Re: GitHub under ongoing DDoS attack

#303
post #283

Earlier quoted context omitted.

So because the Chinese government are being hostile, all the chinese companies innocently doing their own business should have their comms cut off as well? Chinese families should not be able to contact their travelling members? This is definitively the exact same issue - the Chinese government is not the only entity to use the Chinese intertubes.

Did you miss the part in my 20-word comment where I said "I don't think banning countries from the internet is the answer"?

I worded it poorly, but my point was that this is the exact same issue.

Re: GitHub under ongoing DDoS attack

#304
post #290
post #271

Earlier quoted context omitted.

Because Github does not want to be complicit in Chinese government censorship, and if they blocked what that government obviously wants them to block, then they would be.

> Because Github does not want to be complicit in Chinese government censorship I think you are missing the guy's point: what is the difference between Russian censorship and Chinese censorship? Github made a deal with Russia - why not also China?

I know this might soUnd Kafkaesque but here it goes: Internet censorship is extralegal in China and the official stance is to deny its existence. They are known to be somewhat proud of the fact that "we respect internet freedom and never took down any websites hosted overseas". There is going to be no deal because that would be an admission of responsibility.

Re: GitHub under ongoing DDoS attack

#306

Earlier quoted context omitted.

I think there are plenty of people, myself included, who understand how DDoS attacks work. Do you know how X-Prizes work? Hit: Did I say anything about software? [edit: It's odd to me that this would get down voted. Is it offensive? Or are downvoters really that opposed to thinking outside of the box? The X-Prize encourages participation from unexpected directions, precisely where innovation is often found. As the pa…

>Did I say anything about software? Well, you did say: "Who'd like to sponsor? Or should I just spin up a GitHub repo for the code and a kickstarter for the prize money?"

Indeed I did, still no software implication. I was being fairly deliberate about that.

What I'm confused about is what the argument is.

Is it we shouldn't try to find a solution?

I'm sorry if I was unclear that I did not intend to limit the scope of solutions to software, but frankly so what even if I had?

In any case the X-Prize proposal seems quite popular so I'd be happy to set it up, help someone else set it up or in general do anything I can to encourage innovative solutions of any kind, but..

...never tell me the odds.

Re: GitHub under ongoing DDoS attack

#308

Earlier quoted context omitted.

We should never take up arms for a thread that has no human casualties, especially when there are alternatives. If your neighbour enter your home uninvited, because the door is not locked, the first thing you do is ask nicely not to do that. The next thing you do is lock the door. You don't start shooting at them first ...

I'd say cut the internet trunk lines to China... period.. end of story. That would seem to be an appropriate response. Blacklist China's internet traffic completely.

This is why hacker news users are not in politics

Re: GitHub under ongoing DDoS attack

#309
post #230
post #130

Earlier quoted context omitted.

"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.

I agree that it's criminal but that doesn't make it a terrible offense, and far from an "act of war". The damages to GitHub are probably minor in the long run. Nobody will have died or have even been injured. Any one violent crime would rank above this in severity imho.

Bandwidth don't come for free. That's a shit-ton of junk data battering their servers.

Re: GitHub under ongoing DDoS attack

#310
post #169

Earlier quoted context omitted.

If the PRC were merely snooping, and not actively attacking, that equivalence would work. I was also under the impression that this is already in violation of treaty, the only saving grace for the PRC being that it hasn't been proven it's them.

I'm sorry, snooping? Remotely transmitted malware. Hardware caught in transit and infected by malware. Firmware infected with malware at factories. Bricked backbone routers, causing widespread outage during civil war. Hacked phone companies. Stuxnet, a computer worm designed to sabotage industrial centrifuges. A $6 billion trade contract being manipulated in favor of Boeing. A $1.3 billion contract trade contract bei…

> Remotely transmitted malware.

For data acquisition (snooping).

> Hardware caught in transit and infected by malware.

For... hmm... backdoors to data? (Laptops with Stuxnet covered below)

> Firmware infected with malware at factories.

For, yes, transmission snooping. The PRC has also altered routers and other computerized electronics, including those intended for use by militaries in various Western countries.

> Bricked backbone routers, causing widespread outage during civil war.

Yes, by accident [1] while attempting to surveil (snoop). Not sure if disabling Syria's internet is worse or better than China's DNS poisoning which affected everyone... by accident.

> Hacked phone companies.

For what purpose, I wonder?

> Stuxnet, a computer worm designed to sabotage industrial centrifuges.

A. Not done over the internet, done by sneakernet. B. Nuclear reactor facilities in Iran are really not the same as GitHub.

> A $6 billion trade contract being manipulated in favor of Boeing.

That's nefarious, I'll agree... except, the NSA just blew the whistle on Airbus who was bribing Saudi officials. The information was indeed gained from--wait for it--snooping. [2]

> ...Raytheon

Same deal there... The CIA was the whistle blower against the French competition. [3]

> Weakening products and standards that Internet users.[sic]

LOL.

Of the two actions you do cite that aren't surveillance, one has nothing to do with the internet and the other was for the purpose of surveillance. So no, the U.S. government's surveillance program is not the same as the PRC performing a DDoS attack on Github.

  [1] http://gizmodo.com/snowden-the-nsa-turned-off-syrias-internet-1621068611
  [2] http://news.bbc.co.uk/2/hi/europe/820758.stm
  [3] http://en.wikipedia.org/wiki/ECHELON#cite_note-60
Post reply on HN