Live data from Hacker News

China's Man-On-the-Side Attack on GitHub

netresec.com

221–230 of 323 posts

Re: China's Man-On-the-Side Attack on GitHub

#222

Earlier quoted context omitted.

On which side are you ._.

Engineers don't care what side anybody is on, as long as the tech works.

Really?

We knew the world would not be the same. A few people laughed, a few people cried, most people were silent. I remembered the line from the Hindu scripture, the Bhagavad-Gita... "Now, I am become Death, the destroyer of worlds."

Any engineer worth his salt absolutely understands the consequences of their actions on the world. Sometimes they understand a bit too late.

Re: China's Man-On-the-Side Attack on GitHub

#223
post #186

Earlier quoted context omitted.

Hey, I didn't see it was you! Still at Douban? I know what you mean in terms of "boiling milk" - in that respect I agree. I keep thinking these days of that old saying of China as a sleeping elephant; instead I think the people are the sleeping elephant. I think the government's strategy relies a lot on ignorance and apathy, but if even half of these stories we read as standard on NYTimes etc made it into the public…

(Yes, still working for Douban) > if you decided to fight one of those laws, you could do it openly and publicly and in principle it would be a fair fight. Yes, but here you may have assumed that "openly and publicly" is a precondition for fairness. I do not think openness and publicity of fights is the only way to get fairness. Or at least this can be discussed and we should allow that, on one side openness is often…

I don't know, I'm kind of skeptical of the ability of closed elites from anywhere doing things that are fair. We've seen the last few years how tightly linked elites in European/US societies have been evading tax responsibilities, trampling on constitutions or laws to spy on citizens, protecting those responsible for the 2008 crisis, fabricating evidence for various invasions etc. I just mean to say that temptation is too great - openness is too often a toothless tool, but it helps check those elites when their interests veer wildy away from the common good.

China is weird because it's so closed, and it's often tempting to say that the elites here are doing a pretty good job of doing what's best for the people. Until you read about how much money they are making personally from abusing their positions.

Re: China's Man-On-the-Side Attack on GitHub

#224

Since the question of "why" and "how" is coming up again, here's a quick summary I posted on reddit: From a few different analysis on HN and elsewhere... Baidu has an analytics product and an ads product, much like Google Analytics and Google AdSense, which are used on all kinds of websites via Javascript. China has set the Great Firewall of China to modify some of Baidu's assets so that any non-Chinese IP gets a mod…

> Another is that you should never ever have any webpage configured to load any resources from a server hosted within China IP address space as it is vulnerable to this sort of attack by the Chinese government.

Yep. Baidu are a NASDAQ listed company, while they may not be the malicious actor here, they still have a responsibility to ensure their networks are not used to attack others - which they don't seem to be taking seriously.

Until Baidu take steps to ensure their networks are not used to attack others, we should drop their packets: https://news.ycombinator.com/item?id=9295617

Re: China's Man-On-the-Side Attack on GitHub

#225
post #156
post #126

Earlier quoted context omitted.

The attack is not on Baidu, but via Baidu. Whoever is the attacker appears to control the great firewall of China. Who else would that be but the Chinese government?

The Honker Union http://en.wikipedia.org/wiki/Honker_Union and/or the Red Hacker Alliance http://en.wikipedia.org/wiki/Red_Hacker_Alliance

The line seems to be blurry - as I'm sure it is around the world when it comes to state level "hacking".

http://en.wikipedia.org/wiki/Honker_Union#Relationship_with_...

Re: China's Man-On-the-Side Attack on GitHub

#226
post #222

Earlier quoted context omitted.

Engineers don't care what side anybody is on, as long as the tech works.

Really? We knew the world would not be the same. A few people laughed, a few people cried, most people were silent. I remembered the line from the Hindu scripture, the Bhagavad-Gita... "Now, I am become Death, the destroyer of worlds." Any engineer worth his salt absolutely understands the consequences of their actions on the world. Sometimes they understand a bit too late.

He still went along with it.

Re: China's Man-On-the-Side Attack on GitHub

#227

Earlier quoted context omitted.

It would also hurt american, or european, or any nationality of business that uses baidu to get more insight into chinese visitors. Baidu is certainly most popular within china, but not exclusive to them.

Google Analytics does all that, no worries

Google Analytics is, sometimes, blocked by the GFW – so, if you already sell out your users to Google, using Baidu wouldn’t be an unrealistic use case anymore.

Re: China's Man-On-the-Side Attack on GitHub

#228

Since the question of "why" and "how" is coming up again, here's a quick summary I posted on reddit: From a few different analysis on HN and elsewhere... Baidu has an analytics product and an ads product, much like Google Analytics and Google AdSense, which are used on all kinds of websites via Javascript. China has set the Great Firewall of China to modify some of Baidu's assets so that any non-Chinese IP gets a mod…

Wondering if Github has reported this to law enforcement agencies and knowing origin of attack - how will FBI etc proceed? Will we get a statement from administration itself on the lines of Sony hacking or trade relations are too big to endanger?

Re: China's Man-On-the-Side Attack on GitHub

#229
post #224

Since the question of "why" and "how" is coming up again, here's a quick summary I posted on reddit: From a few different analysis on HN and elsewhere... Baidu has an analytics product and an ads product, much like Google Analytics and Google AdSense, which are used on all kinds of websites via Javascript. China has set the Great Firewall of China to modify some of Baidu's assets so that any non-Chinese IP gets a mod…

> Another is that you should never ever have any webpage configured to load any resources from a server hosted within China IP address space as it is vulnerable to this sort of attack by the Chinese government. Yep. Baidu are a NASDAQ listed company, while they may not be the malicious actor here, they still have a responsibility to ensure their networks are not used to attack others - which they don't seem to be tak…

Baidu network is not used. The response is altered as the trafic goes out of China. The only thing they can do is hosting http://hm.baidu.com in another country.

Re: China's Man-On-the-Side Attack on GitHub

#230

Earlier quoted context omitted.

No, the difference is that in the west you can access Russia Today ( http://www.rt.com ) and China Daily ( http://www.chinadaily.com.cn/en/ ), state-owned propaganda channels who delight in publishing anything that would make the U.S. look bad, and in China you can't access the NYT which helped break the Snowden stuff. The Guardian is owned by a trust who have legal obligations based on fair and balanced reporting, a…

Oddly, the Guardian is in fact not owned by a trust any more. It's owned by a private corporation that calls itself The Scott Trust, but it stopped being an actual trust in 2008.

That's true, though they seem to be trying to set up the corporation in a trust-like way. It has a corporate charter that prohibits dividend payments, makes it difficult to cash out any profits, requires the company to treat its newspaper assets in certain ways, etc. I don't know how bulletproof that arrangement is, though.
Post reply on HN