Live data from Hacker News

China's Man-On-the-Side Attack on GitHub

netresec.com

81–90 of 323 posts

Re: China's Man-On-the-Side Attack on GitHub

#81

Does baidu have any say in this at all? Were they hacked to include this script or they just passively allowed it?

The Great Firewall of China can be used to "weaponize" any website passing through it. So, it can be used to inject a malicious script on Baidu delivered to non-Chinese IPs (as we see here) or Chinese IPs. It can also be used to inject a malicious script into Google AdSense for Chinese IPs as well as China has control of a digital certificate provider accepted by all major browsers and operating systems. One they hav…

And remember to remove the CNNIC Root CA from your certificate store unless you know you need it.

Re: China's Man-On-the-Side Attack on GitHub

#82
post #23
post #10

I still don't really get it. What's the actual goal behind the attack? When the Chinese government decides to block a website, I can at least understand their motivations, as bad as they may be. But DDOSing Github just seems to be pissing the whole world off for a few hours without any actual long term consequences.

Actually, someone here (who I cannot remember) said quite eloquently yesterday that our biggest export--and "influence" on the world--is culture. For the first time I realized that pissing people off may, in fact be the objective as the other reply stated. China and Russia are both (quite unique) examples of countries with an unfathomable degree of control over their citizens. It can be hard to grasp occasionally, co…

> the entire reality they see and what they believe to be true is heavily distorted

I have to disagree with others that this part of your comment is a bit too strong. I lived in China for two years and many people I talked to would say something like "We admire America because it is so free, our country is just so corrupt" or whisper something like "when the US says our human rights are bad, we agree."

Re: China's Man-On-the-Side Attack on GitHub

#83

So assuming that the Chinese government weaponized their firewall, the question is why are they using it in such a transparent way? Github is pretty firmly in the camp of open information, and used by nearly every web software engineer in the world. Surely they're not going to succeed at censoring these projects. As an attempt to project power and send some sort of warning, something about it just seems like a pretty…

> As an attempt to project power and send some sort of warning, something about it just seems like a pretty flawed strategy.

I've been wondering about that myself. Perhaps the lesson to be taken away by most is that if you're not Github, you might not be able to effectively counter such an attack. That could lead to self-censorship.

Re: China's Man-On-the-Side Attack on GitHub

#84
post #79
post #70

Earlier quoted context omitted.

The attack is still going on. Details at https://status.github.com/messages They describe what they're doing to mitigate it. The latest message is 0:09 UTC Hour 118: Mitigation remains effective and service is stable.

Yes but they don't explain what the mitigation is.

During an ongoing attack? I wonder why not...

Re: China's Man-On-the-Side Attack on GitHub

#85
> China's Man-on-the-Side Attack on GitHub > and can conclude that China is using their active and passive network infrastructure

China is a country that has 1.35B people in it. I guarantee you that 99.9% of those people had nothing to do with this attack. Can we stop using "China" and be more specific? It feels like it's blaming innocent people and possibly an entire innocent country.

Chinese attackers? The Chinese government? People outside China who hacked Chinese internet infrastructure? At this point can we even be certain who specifically is to blame?

Re: China's Man-On-the-Side Attack on GitHub

#86
post #10

I still don't really get it. What's the actual goal behind the attack? When the Chinese government decides to block a website, I can at least understand their motivations, as bad as they may be. But DDOSing Github just seems to be pissing the whole world off for a few hours without any actual long term consequences.

I think you answered your own question..

> What's the actual goal behind the attack? > pissing the whole world off for a few hours

Re: China's Man-On-the-Side Attack on GitHub

#87
post #20
post #17

Earlier quoted context omitted.

Except this particular attack is not coming from Chinese IPs, rather from visitors of Chinese websites from outside China.

right, which is why unfortunately github couldn't counter by piping in some anti-china propaganda or something. As a sidenote though, VPN users are probably also affected.

Chinese VPN users are absolutely affected, and in fast this puts more pressure on Chinese-used VPN services, and to a lesser extent the users, too.

Re: China's Man-On-the-Side Attack on GitHub

#88
post #45
post #23

Earlier quoted context omitted.

Actually, someone here (who I cannot remember) said quite eloquently yesterday that our biggest export--and "influence" on the world--is culture. For the first time I realized that pissing people off may, in fact be the objective as the other reply stated. China and Russia are both (quite unique) examples of countries with an unfathomable degree of control over their citizens. It can be hard to grasp occasionally, co…

> the entire reality they see and what they believe to be true is heavily distorted--in that, it is defined by the vision of the oligarchy and information is carefully controlled to produce a desired set of beliefs. That's pretty much how I feel about the Fox-watching population of the US.

It's also how I feel about the CNN-watching population of the US.

Re: China's Man-On-the-Side Attack on GitHub

#89
post #79

Earlier quoted context omitted.

Yes but they don't explain what the mitigation is.

During an ongoing attack? I wonder why not...

Right. Not looking for specifics. My curiosity would be satisfied by something like "we've reached out to Baidu and they've done X and Y. Meanwhile, traffic has decreased so we've unblocked the affected repos."

Just a bit more transparency on the situation.

Re: China's Man-On-the-Side Attack on GitHub

#90

> China's Man-on-the-Side Attack on GitHub > and can conclude that China is using their active and passive network infrastructure China is a country that has 1.35B people in it. I guarantee you that 99.9% of those people had nothing to do with this attack. Can we stop using "China" and be more specific? It feels like it's blaming innocent people and possibly an entire innocent country. Chinese attackers? The Chinese…

Nobody is sitting here equating the word "China" with the entirety of the Chinese people.
Post reply on HN