Live data from Hacker News

China's Man-On-the-Side Attack on GitHub

netresec.com

261–270 of 323 posts

Re: China's Man-On-the-Side Attack on GitHub

#261
post #238

Earlier quoted context omitted.

Does that mean we should drop everything coming from US prefixes also because the NSA uses them for man-on-the-side attacks?

If there is a specific infrastructure being leveraged by the someone to attack someone else, and the owner of the infrastructure is not taking steps to prevent its misuse, then yes, of course. Edit: yes, throwaway7767, this means any company. However LinkedIn, in this case, was being spoofed, and LInkedIn's infrastructure was not used: http://www.spiegel.de/international/world/ghcq-targets-engin... Edit 2: no, throwa…

Apparently I can now reply further into the thread, must be a timed thing.

> Edit: yes, throwaway7767, this means any company. However LinkedIn, in this case, was being spoofed, and LInkedIn's infrastructure was not used: http://www.spiegel.de/international/world/ghcq-targets-engin....

LinkedIn was indeed being spoofed, which is exactly what was being done to baidu in this case we are discussing. So it seems to be we now agree that blocking baidu would not be appropriate?

> Edit 2: no, throwaway7767, Baidu's infrastructure - their bandwidth, their customers, and location within the Chinese Firewall are being used to attack GitHub. Baidu has control over where they locate their servers. Baidu are not exercising that control.

And in what way is this different than the attack on LinkedIn we were discussing? Please be specific.

I've already said I disapprove of these methods regardless of who applies them, but you have not seen fit to specifically state that companies like linkedin should move all their servers outside the US/UK/FVEY countries, reserving that course of action only for chinese companies.

Re: China's Man-On-the-Side Attack on GitHub

#262

Earlier quoted context omitted.

It is rather stupid to equate the degree of media manipulation in the West vs. China and Russia.

I didn't equate them. I said mind control is worse in the West. And, I cited a detailed analysis of the topic.

The fact that you at least have an analysis article to cite from kinda proves he was on point, and you are not, not entirely.

Which control is more ultimate, you can type some but mainstream ignores you or you cannot type at all?

Re: China's Man-On-the-Side Attack on GitHub

#263
post #71

Earlier quoted context omitted.

> [China] an unfathomable degree of control over their citizens You obviously haven't been there. I think Chinese gov have the same level of control over its citizens as France: very erratic, sometime works well, some people try to play with fire, but overall the Chinese are all but lobotomized robots in the hands of a few puppet masters. There's over 500 strikes a year in China, not counting all the ones not big eno…

And you haven't been to France Does France has a Great Firewall on the Internet? Does France allow people to study about their actions in Algeria, for example? They do. (or you're part of the conspiracy, I can't exclude that)

Great Firewall is not there because NSA is.

Re: China's Man-On-the-Side Attack on GitHub

#264

Since the question of "why" and "how" is coming up again, here's a quick summary I posted on reddit: From a few different analysis on HN and elsewhere... Baidu has an analytics product and an ads product, much like Google Analytics and Google AdSense, which are used on all kinds of websites via Javascript. China has set the Great Firewall of China to modify some of Baidu's assets so that any non-Chinese IP gets a mod…

The takeaway from this attack is the same as we got from the Snowden disclosure: Nations will abuse network services that is located on their borders. They will hack-tap-and-steal, modify, block, and use any method available to distribute malware. Any action is viable so long there is a target to attack which could produce political, economical or military advantages.

I suspect we will reach a point where treaties are needed to protect the basic building blocks of the Internet. We can't expect nations to respond by sending in military force, or voluntary give up the benefits from this kind of attacks. This leaves few options left if one want the economic benefits from cloud services and similar shared-network concepts.

Re: China's Man-On-the-Side Attack on GitHub

#265
post #208

Earlier quoted context omitted.

You'd think, wouldn't you. Or instead simply blacklist Baidu's analytics code completely. That will only hurt Chinese businesses using Baidu's product, and no-one else.

I agree and I even think that this will be unavoidable, if that kind of abuse keeps going on. Government influence aside, Baidu would be free to host their analytics callbacks for the outside world outside of the GFW. If they stay accomplice to this kind of attack, no matter if forced or willingly, they will suffer.

Given the amount of ad bourne malvertising that is floating around, a content based blacklist of javascript would be a good thing.

Re: China's Man-On-the-Side Attack on GitHub

#266
post #156

Earlier quoted context omitted.

The Honker Union http://en.wikipedia.org/wiki/Honker_Union and/or the Red Hacker Alliance http://en.wikipedia.org/wiki/Red_Hacker_Alliance

The line seems to be blurry - as I'm sure it is around the world when it comes to state level "hacking". http://en.wikipedia.org/wiki/Honker_Union#Relationship_with_...

Sure, but the Chinese government has far more sophisticated ways of taking down sites so their own citizens can't access them, and they're not afraid to use them - even against big name sites. And in fact they often do, to help local companies providing the same offerings to prosper.

The current DDoS attack just strikes me as too crude a method when they have so many other options available.

If you were going to argue that it's just a retaliation towards GitHub for hosting these projects, then once again there are others sites the government is far more concerned about and they could use DDoS to bring them down with far less publicity than what the GitHub DDoS is generating.

It just doesn't seem to make sense from either the method being used or the motivation behind the attacks.

Re: China's Man-On-the-Side Attack on GitHub

#267

> China's Man-on-the-Side Attack on GitHub > and can conclude that China is using their active and passive network infrastructure China is a country that has 1.35B people in it. I guarantee you that 99.9% of those people had nothing to do with this attack. Can we stop using "China" and be more specific? It feels like it's blaming innocent people and possibly an entire innocent country. Chinese attackers? The Chinese…

People are as much responsible for their governments as the governments are responsible for their people. You can’t let a couple thugs run your country and then say “oh I never liked them, so don’t blame me!!111” when someone points out that they’re thugs.

Re: China's Man-On-the-Side Attack on GitHub

#268

Earlier quoted context omitted.

>can't stop a little 300 person operation. Police forces can infiltrate world-wide gangs. What's stopping China from infiltrating Github if this DDoS doesn't work out?

Is there any evidence of China infiltrating Microsoft or other major OS vendors?

2011 Google Incident. Look it up

Re: China's Man-On-the-Side Attack on GitHub

#269
post #222

Earlier quoted context omitted.

Engineers don't care what side anybody is on, as long as the tech works.

Really? We knew the world would not be the same. A few people laughed, a few people cried, most people were silent. I remembered the line from the Hindu scripture, the Bhagavad-Gita... "Now, I am become Death, the destroyer of worlds." Any engineer worth his salt absolutely understands the consequences of their actions on the world. Sometimes they understand a bit too late.

hey buddy

Re: China's Man-On-the-Side Attack on GitHub

#270
"Based on reports we've received, we believe the intent of this attack is to convince us to remove a specific class of content."

Does anyone know what that "specific class of content" is, or can shed some light over the motivation of the attacks?

Post reply on HN