Live data from Hacker News

China's Man-On-the-Side Attack on GitHub

netresec.com

191–200 of 323 posts

Re: China's Man-On-the-Side Attack on GitHub

#191

Earlier quoted context omitted.

They are back on github now; they were indeed temporarily changed to return only alert("WARNING: malicious javascript detected on this domain"); (or something similar). I saw this myself.

They were still online, only the URL with a trailing slash was replaced. Links to the repository on GitHub itself were still working.

Ah, thank you for the correction.

Re: China's Man-On-the-Side Attack on GitHub

#192

For me the most interesting thig about this incident is how the GFW is being used offensively. Most other governments so far have protested online censorship from a kind of moral standpoint, but not from a security standpoint per se. Now it's quite clear the GFW is being leveraged offensively - did anyone spot this capability previously?

It only really ramped up this year. http://furbo.org/2015/01/22/fear-china/

Don't know why your comment has been voted down, that's an interesting link and blog post and totally relevant to this thread :\

Re: China's Man-On-the-Side Attack on GitHub

#193

Earlier quoted context omitted.

The HK protests were interesting recently for that reason - the protestors had the momentum, and the governments first reaction if it was mainland China would probably be to crush it. They let it boil over, and eventually the momentum was lost and anti-protestor sentiment took over. Whether that was by design or 'helped along' is another issue, but it showed how popular protests can sometimes just sour if left to the…

Occupy Wall Street comes to mind as another example. NYC sentiment turned rather quickly against that movement once the public delectation, rape allegations and the inconvienient even caused by protestors started to boil over.

At university my friend was studying police tactics dealing with football hooligans and riots in the UK - they were slowly changing their tactics from full-on horse charges and batons waving to a very tai chi style light touch. Generally speaking the moderates would get bored and go home and then leave only the hardcore, who were then easier to identify and target. The light touch is a fantastic PR tool too because it shows any gov as tolerant and open.

Re: China's Man-On-the-Side Attack on GitHub

#194

If anyone from GitHub is reading this, I know that many of us would like to help. I imagine that the mitigation of this attack has been very costly. Is there a place we can donate to help offset the cost of this attack? Maybe I will purchase a subscription, but a one time payment would be preferable for many of us.

The've raised $100M from a16z about two years ago [1] ? They should be fine without your donation.

[1] https://news.ycombinator.com/item?id=4220353

Re: China's Man-On-the-Side Attack on GitHub

#195
post #181

Earlier quoted context omitted.

If you want to publish your own newspaper, you can. Nobody will stop you. Start your own online video news service, weblog or nes site - nobody will stop you. Post whatever you like to Reddit, or any other discussion platform. In China and Russia you cannot do these things. Published mdeia are strictly monitored and censored. The state employs thousands of astroturfers to flood social media with pro-government messag…

Yet that Guantanamo ex-prisioner has his book for sale everywhere except in the US... Care to guess why it isn't for sale in the US?

A handful of books banned for a few individual legal issues does not make for a suppressive state. Are you seriously arguing that the USA is more suppressive of coimmunications and publications that China? Really?

Re: China's Man-On-the-Side Attack on GitHub

#196

Earlier quoted context omitted.

One solution that comes to mind for this is for CDN's to have an edge node just outside of the great firewall of China. Even with a simple edge side include, the impact on Github's servers should be near zero.

This won't work because it's browsers outside of China that are being hijacked when browsing Baidu Analytics-using sites.

That's a fair point...

Still, this is a read-based DoS. It should be fairly easy to mitigate with a CDN...

Re: China's Man-On-the-Side Attack on GitHub

#197
post #23

Earlier quoted context omitted.

Actually, someone here (who I cannot remember) said quite eloquently yesterday that our biggest export--and "influence" on the world--is culture. For the first time I realized that pissing people off may, in fact be the objective as the other reply stated. China and Russia are both (quite unique) examples of countries with an unfathomable degree of control over their citizens. It can be hard to grasp occasionally, co…

The difference between the U.S. and China/Russia is that the people in China/Russia know the media is controlled by the powers that be. Here, our press is also "defined by the vision of the oligarchy and information is carefully controlled to produce a desired set of beliefs." We just believe that it's free. See: http://en.wikipedia.org/wiki/Manufacturing_Consent

No, the difference is that in the west you can access Russia Today (http://www.rt.com) and China Daily (http://www.chinadaily.com.cn/en/), state-owned propaganda channels who delight in publishing anything that would make the U.S. look bad, and in China you can't access the NYT which helped break the Snowden stuff. The Guardian is owned by a trust who have legal obligations based on fair and balanced reporting, and all TV news in the UK - including Murdoch's channels - have a legal obligation to not editorialised, underpinned by a legal system that's been sticking two fingers to vested interests since the Magna Carta. Your sense of perspective is broken.

Re: China's Man-On-the-Side Attack on GitHub

#199
post #9

Earlier quoted context omitted.

"... should be the primary duty of our government." Fixed it? Although it's interesting to think about. Actual government retaliation would/could be seen as war provocation, especially if China holds on to any plausible deniability. Cyber warfare is currently very hard to prove, but even harder to hold accountable for. Even with DPRK, and our little shut-down-the-"internet" quiet retaliation thing that happened a few…

A government doesn't have to react offensive against threats. It's also possible to provide defensive measures. In this specific case it could provide infrastructure, computing resources and personal to fend off the attack.

Exactly, that's where these vast NSA's datacenters could make sense and actually do something useful.
Post reply on HN