Live data from Hacker News

Pin-pointing China's attack against GitHub

blog.erratasec.com

41–50 of 144 posts

Re: Pin-pointing China's attack against GitHub

#41

China is the second most powerful country in the world. Do people really think they are that stupid ? They are not going to attack an American company using infrastructure that anyone can track back to them. This Github DDoS has got to be the work of someone trying to frame the Chinese government. Has anyone considered that angle ?

Take a look at this brand new executive order authorizing economical and financial sanctions against global "cyber threats": https://www.whitehouse.gov/blog/2015/04/01/our-latest-tool-c... This GitHub business looks more and more like a false flag operation.

How does 'economical and financial sanctions' equate to 'Whitehouse gives order to start false flag operation against github'?

The more that comes out and the more silence there is from the Chinese government the less it looks like a false flag operation. Usually the victim of a false flag operation (China in this case, not github) would be very adamant about its non-involvement and would work very hard to expose the originator.

Re: Pin-pointing China's attack against GitHub

#42

Earlier quoted context omitted.

Take a look at this brand new executive order authorizing economical and financial sanctions against global "cyber threats": https://www.whitehouse.gov/blog/2015/04/01/our-latest-tool-c... This GitHub business looks more and more like a false flag operation.

How does 'economical and financial sanctions' equate to 'Whitehouse gives order to start false flag operation against github'? The more that comes out and the more silence there is from the Chinese government the less it looks like a false flag operation. Usually the victim of a false flag operation (China in this case, not github) would be very adamant about its non-involvement and would work very hard to expose the…

Yes, just like if Glenn Beck really did not rape and murder a young girl in 1990 he would be very adamant about his non-involvement and would work very hard to expose the actual culprit: http://en.wikipedia.org/wiki/Beck_v._Eiland-Hall

Re: Pin-pointing China's attack against GitHub

#43

Earlier quoted context omitted.

How does 'economical and financial sanctions' equate to 'Whitehouse gives order to start false flag operation against github'? The more that comes out and the more silence there is from the Chinese government the less it looks like a false flag operation. Usually the victim of a false flag operation (China in this case, not github) would be very adamant about its non-involvement and would work very hard to expose the…

Yes, just like if Glenn Beck really did not rape and murder a young girl in 1990 he would be very adamant about his non-involvement and would work very hard to expose the actual culprit: http://en.wikipedia.org/wiki/Beck_v._Eiland-Hall

I'm sorry, I really do not see the parallel here.

A parody is just that, we're talking about a several day long real attack here.

And if you read that article you'll see Beck sued to get the domain. So it's not like he ignored it, and besides it was obvious from the beginning that he wasn't the one that registered the domain.

Re: Pin-pointing China's attack against GitHub

#44
post #23

I have a question with the method, hypothetically, if I am the attacker, I know the ttls of each packets tha tis passing through, right? So when I get a packet with ttl so small that won't survive long enough to reach the target, instead of altering, I just leave it along. So the probe will never know where I am in the route.

But upstream providers within the TTL range will. And during a DDoS like this you can bet that everybody in the chain that is on the good side is in constant communication.

Re: Pin-pointing China's attack against GitHub

#45
post #20
post #12

That the server is located in China doesn't proof anything.

This analysis doesn't just prove the attack orriginated in China, it shows that it takes place immediately inside the first Chinese network the connection reaches on it's way into China. The second piece of analysis shows that this is the same network layer in which the network blocking performed by the Great Firewall occurs. So the great firewall and this attack are both being implemented at the same point in the ne…

I think an interesting question is how likely it is that some of the great firewall is compromised.

(It could be by some party outside of China, or by some group inside of the Chinese government that does not have an official mandate to use it for things like the Github attack)

Re: Pin-pointing China's attack against GitHub

#46
post #13

Is there a statement from github what they think who did the ddos?

No and there probably won't be. Them publicly saying they were being attacked by the Chinese government would put them on some seriously questionable legal ground. They definitely went the right route by not saying anything.

Which laws would they be violating by announcing they were attacked by China?

Re: Pin-pointing China's attack against GitHub

#47

To say that the "Chinese government" is involved I think understates the situation. We know as fact that their army has invested considerable time and money in a cyberwarfare unit. And that the company that operates the Firewall is a military contractor. When Sony was hacked a few months ago, the media couldn't wait to label it a "terrorist act" by North Korea. I just now searched Google News for "github terrorism".…

>But is "terrorism" even the correct word for this?

Don't use that word. It's barely even a word any more, its become one of those weaponized magic symbols used for mind control. See also "freedom", "globalization", "sharing", "choice" and so on.

Instead, you can just use words like "murder", "destruction of infrastructure" and the like.

Re: Pin-pointing China's attack against GitHub

#48

Earlier quoted context omitted.

I apologize because I have not had time to really looking into this closely, but I think you are correct that the author's conclusions need to be reviewed. He repeatedly says that it is a man in the middle attack, but the link he points to says it is a man on the side attack. This is a very different beast: a man on the side attack does not rewrite packets, but rather uses it's position on the backbone to send replac…

The man in the middle attack was injecting javascript to recruit unwitting man on the side attackers against github. github was not being MITM'd, but its "attackers" were. edit: above may be imprecise. I went back and read the original more closely. they note that if they artificially drop an injected packet, it doesn't get resent (and hence the conclusion that it's man on the side), but they don't mention whether th…

Yes, I was wondering whether the original packets arrive or not as well. I'd love to see the traces. In my quick read of the this article I couldn't understand the method that they used to make their determination. Was it the bad packets or the good packets that had the TTL rewritten? The fact that there is a system rewriting packets does not necessarily imply it is an attack. I once wrote a SIP client and the local ISP actually rewrote my headers -- I had a bug in the header and just sending it through the network rewrote it so that it was fixed. This was in Canada. As a result, I have absolutely no doubt that packets are being rewritten all over the place, not just in China. Detecting this is not proof in itself that this is the origin of the attack.

Re: Pin-pointing China's attack against GitHub

#49

To say that the "Chinese government" is involved I think understates the situation. We know as fact that their army has invested considerable time and money in a cyberwarfare unit. And that the company that operates the Firewall is a military contractor. When Sony was hacked a few months ago, the media couldn't wait to label it a "terrorist act" by North Korea. I just now searched Google News for "github terrorism".…

>But is "terrorism" even the correct word for this? Don't use that word. It's barely even a word any more, its become one of those weaponized magic symbols used for mind control. See also "freedom", "globalization", "sharing", "choice" and so on. Instead, you can just use words like "murder", "destruction of infrastructure" and the like.

You forgot 'communism'.

Re: Pin-pointing China's attack against GitHub

#50

Earlier quoted context omitted.

>But is "terrorism" even the correct word for this? Don't use that word. It's barely even a word any more, its become one of those weaponized magic symbols used for mind control. See also "freedom", "globalization", "sharing", "choice" and so on. Instead, you can just use words like "murder", "destruction of infrastructure" and the like.

You forgot 'communism'.

[deleted]
Post reply on HN