Live data from Hacker News

China's Man-On-the-Side Attack on GitHub

netresec.com

71–80 of 323 posts

Re: China's Man-On-the-Side Attack on GitHub

#71
post #23

Earlier quoted context omitted.

Actually, someone here (who I cannot remember) said quite eloquently yesterday that our biggest export--and "influence" on the world--is culture. For the first time I realized that pissing people off may, in fact be the objective as the other reply stated. China and Russia are both (quite unique) examples of countries with an unfathomable degree of control over their citizens. It can be hard to grasp occasionally, co…

> China and Russia are both (quite unique) examples of countries with an unfathomable degree of control over their citizens. It can be hard to grasp occasionally, coming from a western mindset but for the vast majority within said countries, the entire reality they see and what they believe to be true is heavily distorted--in that, it is defined by the vision of the oligarchy and information is carefully controlled t…

> [China] an unfathomable degree of control over their citizens

You obviously haven't been there. I think Chinese gov have the same level of control over its citizens as France: very erratic, sometime works well, some people try to play with fire, but overall the Chinese are all but lobotomized robots in the hands of a few puppet masters. There's over 500 strikes a year in China, not counting all the ones not big enough to be counted. I have seen streets of pedestrians walking against policemen, who were sweating of fear. Right now the prez is quite appreciated and trusted by the people, so he probably has some level of control, but this is earned by its fight against corruption, and not by some matrix-like brainwashing system.

Re: China's Man-On-the-Side Attack on GitHub

#72
post #59

Earlier quoted context omitted.

Hi Djent, Would you mind sending an email to support@github.com with details on what you were doing when that happened? Thanks

It's happening for me constantly - just clicking the link from the discussion - I get a (very) slow page load, then the unicorn page. I'm assuming it's a timeout on the backend.

Same here.

Re: China's Man-On-the-Side Attack on GitHub

#74
post #4

Earlier quoted context omitted.

https://github.com/cn-nytimes/ and https://github.com/greatfire/ host information about and software for circumventing the Chinese government's internet censorship systems -- which, among many other things, blocks access to, eg, Google, and The New York Times. Apparently they (the Chinese government) are not willing to entirely block Github traffic in the same way (presumably as an important tool for their software i…

> information about and software for circumventing the Chinese government's internet censorship systems -- which, among many other things, blocks access to, eg, Google, and The New York Times. The actual impact of the attack was to have thousands of news outlets and discussion forum sites mention and link to the github repos that offer circumvention. Further, by attacking Github, it's guaranteed that many of the most…

> Of course the Chinese government knows this and was likely not responsible for the attack.

This is an example of the logical fallacy of "argumentum ad stultum", or "appeal to stupidty".

It goes like this:

- X would be stupid. - No one would ever do anything stupid. : Therefore no one would ever do X.

There are so many counter-examples to this argument that they hardly bear mentioning. People do stupid things every day of the week and twice on Sundays. Organizations multiply stupidity as often as they moderate it.

It may be that this wasn't the Chinese government, but pointing out that it would be stupid for them to do so is not an argument against it at all.

Re: China's Man-On-the-Side Attack on GitHub

#75
For me the most interesting thig about this incident is how the GFW is being used offensively. Most other governments so far have protested online censorship from a kind of moral standpoint, but not from a security standpoint per se. Now it's quite clear the GFW is being leveraged offensively - did anyone spot this capability previously?

Re: China's Man-On-the-Side Attack on GitHub

#76
post #41

Earlier quoted context omitted.

That's a big freaking gamble. How effective does Github's mitigation need to be to make the costs tolerable? They're already using a full 1% of the traffic to ddos, they can only double that 7 times. Really, at this point Github could probably put together a really nice blacklist of baidu users outside of china, and whitelist those that actually use the service. I can think of a couple of cute ways to accelerate the…

Side question, does GitHub run ruby on rails? If so, I'm pretty impressed.

They are on Rails 3 which is pretty old for Rails standards and they got there recently. See http://shayfrendt.com/posts/upgrading-github-to-rails-3-with...

This is their architecture in 2009 https://github.com/blog/530-how-we-made-github-fast Couldn't find anything more recent.

Re: China's Man-On-the-Side Attack on GitHub

#77
If anyone from GitHub is reading this, I know that many of us would like to help. I imagine that the mitigation of this attack has been very costly. Is there a place we can donate to help offset the cost of this attack? Maybe I will purchase a subscription, but a one time payment would be preferable for many of us.

Re: China's Man-On-the-Side Attack on GitHub

#78
post #38

"Our analysis shows that only about 1% of the requests for the Baidu Analytics script are receiving the malicious javascript as response. So in 99% of the cases everything behaves just like normal." The way I see it, this has been a diagnostic test by the Chinese government, ensuring they have the power to globally take down any website (or servers) they please.

Possibly. But whoever's behind it end up looking kind of bad, since Github has not capitulated.

Re: China's Man-On-the-Side Attack on GitHub

#79
post #70
post #31

I wonder how GitHub mitigated the attack so successfully. I can't find any baidu scripts using the injected code anymore (in fact the original tracking scripts on baidu's own domain return nothing), and GitHub is now serving the two repos that were originally targeted. What happened? Whatever it is, I'm glad they were able to mitigate the attacks.

The attack is still going on. Details at https://status.github.com/messages They describe what they're doing to mitigate it. The latest message is 0:09 UTC Hour 118: Mitigation remains effective and service is stable.

Yes but they don't explain what the mitigation is.

Re: China's Man-On-the-Side Attack on GitHub

#80
post #36
post #31

I wonder how GitHub mitigated the attack so successfully. I can't find any baidu scripts using the injected code anymore (in fact the original tracking scripts on baidu's own domain return nothing), and GitHub is now serving the two repos that were originally targeted. What happened? Whatever it is, I'm glad they were able to mitigate the attacks.

The injection has been stopped and Baidu's script checks if there exists a referer.

[deleted]
Post reply on HN