Live data from Hacker News

GitHub under ongoing DDoS attack

status.github.com

321–330 of 352 posts

Re: GitHub under ongoing DDoS attack

#321
post #164

Earlier quoted context omitted.

I think you miss my point. As I see it, the Chinese government are basically blocking Google as a business decision. Take a look at Baidu. You will be amazed at the number of services they offer. On the roads in China you see a lot of Audis and Mercedes. These are mostly driven by Government officials. There are many avenues for Government officials to earn money. I don't know the size of companies like Baidu and Ali…

Your 2 statements has nothing to do with each other. Here take another 50 cent.

I am sorry. I have to let you connect the dots. I have a university job in China and I don't want to be kicked out of the country. Just follow the money.

Re: GitHub under ongoing DDoS attack

#322
post #241
post #130

Earlier quoted context omitted.

"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.

I hope that by "full support of federal law enforcement, if not the military" you mean whatever cyber defense and possibly offense forces they have. I really hope that nobody thinks this is worth starting a shooting war with a rival nuclear superpower over.

On further thought, you're right. I would not condone any sort of violent response. But a criminal investigation should be made, even if it leads to Chinese authorities.

(Just as we should have criminal investigations over US surveillance programs...).

Re: GitHub under ongoing DDoS attack

#323
post #241

Earlier quoted context omitted.

I hope that by "full support of federal law enforcement, if not the military" you mean whatever cyber defense and possibly offense forces they have. I really hope that nobody thinks this is worth starting a shooting war with a rival nuclear superpower over.

PRC is not (yet) a superpower.

sigh go look up the definition

Re: GitHub under ongoing DDoS attack

#324
post #169

Earlier quoted context omitted.

I'm sorry, snooping? Remotely transmitted malware. Hardware caught in transit and infected by malware. Firmware infected with malware at factories. Bricked backbone routers, causing widespread outage during civil war. Hacked phone companies. Stuxnet, a computer worm designed to sabotage industrial centrifuges. A $6 billion trade contract being manipulated in favor of Boeing. A $1.3 billion contract trade contract bei…

> Remotely transmitted malware. For data acquisition (snooping). > Hardware caught in transit and infected by malware. For... hmm... backdoors to data? (Laptops with Stuxnet covered below) > Firmware infected with malware at factories. For, yes, transmission snooping. The PRC has also altered routers and other computerized electronics, including those intended for use by militaries in various Western countries. > Bri…

>>> For... hmm... backdoors to data?

Backdoors has a lovely side effect, in that they are backdoors. They can be used to take control over devices, as in. That they can also be used for data transfer is a side effect of the active attack called "implanting an backdoor".

But okey, if all those are just snooping and not active attacks, let just assume that PRC gained the information to attack github by snooping. DONE. It is now just snooping as per your definition.

> A DDOS attack on github.

>> except, the PRC just used information, information which was indeed gained from--wait for it--snooping!

In computer security, we have terms to distinguish this. Its called passive and active attacks. PRC and NSA both perform active attacks on other nations infrastructure, businesses, governments and military. The purpose: To gain political, economic and military benefits.

Re: GitHub under ongoing DDoS attack

#325
post #22

Can we be sure it's not Chinese hacktivists seeking justice via a digital sit-in?

Why would Chinese hacktivists want to attack a project which increases their ability to get past the GFW?

Hactivist by itself doesn't imply anti censorship. Just people who hack as a form of activism.

In china there are hacktivists that are against the government and hacktivists that support the government's agenda and who hack for patriotic purposes and to avenge perceived slights against china.

It's a well known phenomenon in china known as red hackers (or the Honker Union: http://en.wikipedia.org/wiki/Honker_Union )

And it's far more likely that they are behind this sort of thing.

People with the skills to be a member of that sort of group have no need for either of the two relatively obscure projects hosted on GitHub to circumvent the GFW.

Re: GitHub under ongoing DDoS attack

#326
post #210
post #153

Hi, foreigner working in Chinese high tech company here. I wonder a bit, on which ground is this attack attributed to Chinese gov? It looks a bit unlikely to me. China has some cyber military but they are more likely to be pragmatic and choose wisely their targets. There's a bunch of script kiddies but they would choose also something else. However it seems possible that many servers hosted in China are not secured a…

The official cyber force of China is not the biggest suspect in most attacks like this. The loosely controlled civilian hacker force (think privateer pirates) launch most ddos-style attacks on foreign soil.

Why would they care about protecting the great firewall?

Re: GitHub under ongoing DDoS attack

#327

Earlier quoted context omitted.

I didn't downvote you but I can see why they did. The way you act is similar to someone running a contest to disprove Turing's proof on the halting problem. If your bandwidth is being filled from the other end, it doesn't matter how sophisticated the filter is at your server. Even if it is theoretically perfect and able to tell which packets came from real requests with 100% accuracy, it will not solve the problem. T…

I understand your position, and I don't want to be offensive. I simply want to be clear. The X-Prize is intended precisely for this type of industry stagnation, and has been very successful at that goal so far. Winners solve unbelievable problems in unbelievable ways. I am, if not an expert, nearly so, and I can say that my first thought is not better filtration. As you rightly point out that is a very hard problem,…

> The X-Prize is intended precisely for this type of industry stagnation

No. Take a look Ansari X-Prize, the first of this kind.

The theoretic foundations for spaceflight were laid out about a century ago, the first flight took place in 1961. So this is something which is very well understood. The prize was, basically, for tweaking the components to make it cheaper.

But you're asking somebody to invent a new method, without providing a theoretical foundation for it to work in.

So this would be like asking to invent a teleporter or faster-than-light travel.

Besides that, other x-prizes were formulated as a contained experiments. E.g. demonstrate that your spacecraft can fly, or provide a program which offers better recommendations.

But what you describe is not an experiment. You actually want participants to go an change how the Internet works. This isn't contained.

So you're being downvoted for being extremely naive. You seem to believe that a kickstarter campaign and a github repo can solve any problem.

Re: GitHub under ongoing DDoS attack

#328
post #143

Earlier quoted context omitted.

Not breaking encryption itself. Breaking encryption to serve malicious scripts.

So breaking encryption is accepted; serving malicious scripts is accepted (it's what happened in this attack), but breaking encryption to serve malicious scripts would be out of limits? That doesn't make much sense.

Serving malicious scripts is very bad, and may not actually be accepted. I know I would hesitate to use baidu analytics after this. But people might come around if they say something about SSL and wont happen again.

If the encryption is then broken and it is done again, then a) it will prove that China did it. Because you can see who signed the certificate. b) it will prove that technical countermeasures are not enough, since the problem is deeper than that.

Re: GitHub under ongoing DDoS attack

#329
post #311

Earlier quoted context omitted.

This isn't the first time [0] China has been accused of using it's filtering to DDoS enemies. It's not a secret weapon really, it's an obvious capability of being able to redirect a large majority of your country's internet traffic at will. [0] http://furbo.org/2015/01/22/fear-china/

China and Chinese have been accused of all sort things. From ten years spent there I can tell you accusing their gov to be stupid is really dumb. Attacking github is the most useless attack they could invent. Therefore it's not them. Or it is a side effect.

Never underestimate the stupidity of a bureaucrat.

Re: GitHub under ongoing DDoS attack

#330
post #265
post #80

Earlier quoted context omitted.

I agree in general, but in this specific case, Beijing can just demand access to Baidu's private keys and MITM all traffic passing through the GFWoC.

Chinese government already has a root CA in all browsers.

> Chinese government* already has a root CA in all* * browsers.

* For definitions of "Chinese government" that includes the Beijing non-profit China Internet Network Information Center, which isn't technically part of the government, but presumably is easily pressured.

* * For definitions of "all browsers" that excludes some minority browsers and those browsers run by users who have disabled the CNNIC root cert.

I have no doubt that the Chinese government has access to the CCNIC root certificate private key if it so chooses, but demanding the private key for an existing domain certificate would provide slightly less traceability and slightly more deniability.

Post reply on HN