Live data from Hacker News

Pin-pointing China's attack against GitHub

blog.erratasec.com

71–80 of 144 posts

Re: Pin-pointing China's attack against GitHub

#71

Earlier quoted context omitted.

A sufficiently sophisticated man in the middle can be anywhere between origin and destination and have arbitrary distribution. Proving that a particular node is responsible for a particular alteration requires using a trusted trust computer to send packets into the great wall on their first hop. The experiment in the article required trusted trust of packets destined for the great wall passing through US infrastructu…

So that experiment would need to be repeated in a distributed manner from as many points of origin as possible. A friend of mine runs a honeypot service that uses servers all around the planet, someone like him would be in a good position to run analysis like this.

Logically, sufficient distribution of testing doesn't negate sufficient distribution of evil demons. Practically, if the evil demon has state actor level resources, it is more likely to have sufficient distribution than an ordinary commercial or private interest.

On the other hand, I don't think it's really necessary to prove with technology that the 中國人民解放軍 is behind this. Diplomatic logic is sufficient. The behavior is simply an internet equivalent to jamming the Voice of America.[1]

Github is broadcasting. The 中华人民共和国 has a sovereign's policies regarding broadcasting. The 中國人民解放軍 executes those policies. Github operates with a business model that ignores sovereigns at its own peril. Calling one sovereign for aid when dealing with another sovereign also carries peril.

Allowing political content in an online community always comes with the risk of trolling and flamewars. A hands off editorial policy only means Github hasn't made a tough decision about what the Github community is not. Decision day can only be put off so long.

[1]: http://en.wikipedia.org/wiki/Voice_of_America

Re: Pin-pointing China's attack against GitHub

#72

To say that the "Chinese government" is involved I think understates the situation. We know as fact that their army has invested considerable time and money in a cyberwarfare unit. And that the company that operates the Firewall is a military contractor. When Sony was hacked a few months ago, the media couldn't wait to label it a "terrorist act" by North Korea. I just now searched Google News for "github terrorism".…

If we are going to use terms like "cyberwarfare", it make logical sense that other military tactics will also be ported over to digital versions. One of those is the classic weapon test, where a nation demonstrate their military power to the world.

China used 1% of the available traffic from a single CDN. Their choice of target might just have been randomly picked from low priority list for the dual purpose of sending a political message.

Re: Pin-pointing China's attack against GitHub

#73

Earlier quoted context omitted.

So that experiment would need to be repeated in a distributed manner from as many points of origin as possible. A friend of mine runs a honeypot service that uses servers all around the planet, someone like him would be in a good position to run analysis like this.

Logically, sufficient distribution of testing doesn't negate sufficient distribution of evil demons. Practically, if the evil demon has state actor level resources, it is more likely to have sufficient distribution than an ordinary commercial or private interest. On the other hand, I don't think it's really necessary to prove with technology that the 中國人民解放軍 is behind this. Diplomatic logic is sufficient. The behavio…

That's the odd thing, they could jam it instantly if they so chose to. The GFWs primary purpose is to limit access to certain urls from within China.

Now of course those repos are intended to circumvent that but once someone has them they are out of reach of the GFW. So blocking those urls at the GFW would seem to be all that's really needed.

Tools like these should be accessible from as many places as possible.

Re: Pin-pointing China's attack against GitHub

#74

China is the second most powerful country in the world. Do people really think they are that stupid ? They are not going to attack an American company using infrastructure that anyone can track back to them. This Github DDoS has got to be the work of someone trying to frame the Chinese government. Has anyone considered that angle ?

[deleted]

Re: Pin-pointing China's attack against GitHub

#75

Earlier quoted context omitted.

You can really only use a method like this to say where a server is not (it can't be halfway around the world because the speed of light limits it), but this is assuming you're communicating directly with the server. The method used to inject these packets on the wire makes this sort of analysis even harder to do this sort of analysis (and if there was concern, appropriate amounts of random delay and noise could be a…

>The method used to inject these packets on the wire makes this sort of analysis even harder to do this sort of analysis I was under the impression that this was a man on the side attack, so they'd sent a bogus SYN-ACK back to you the moment that they saw a SYN. Theoretically, you should still only be dealing with one RTT. >(and if there was concern, appropriate amounts of random delay and noise could be added). I do…

The man on the side they're performing, according to analysis, seems to be letting the initial SYN through to the original server, you get the SYN-ACK back from the actual Baidu server. Then after your ACK and HTTP GET, the other packets are injected. If they wanted to make the attack more subtle, messing with the timing to make it match the original SYN-ACK pair and keeping the right TTL values would make it much harder to detect.

http://www.netresec.com/?month=2015-03&page=blog&post=china%...

Re: Pin-pointing China's attack against GitHub

#76

Earlier quoted context omitted.

> bureaucracies tend to do extremely stupid stuff when looked at from the outside but every cog on the inside thinks that its action makes perfect sense. If this is Chinese doing, the likely ones responsible are the Chinese Intelligence, not their bureaucracy. > Evidence? Occam's Razor. I find it hard to believe that a society with sufficient level of sophistication to obtain $9 trillion GDP[1] would 'accidentally' g…

I question your invocation of Occam's Razor here. Between: 1) the attack is perpetrated by the entity the evidence suggests and 2) the attack was prepetrated by another entity who cleverly used infrastructure of the first entity to frame them for it, applying Occam's Razor would suggest situation #1 in lieu of evidence to the contrary.

On closer examination, you seem to be correct. Without insight into how Chinese secret service works the simplest explanation is that the attack was likely perpetrated by them and that is what we must assume to be of highest probability. I will leave my comments here for posterity.

Re: Pin-pointing China's attack against GitHub

#77

Earlier quoted context omitted.

Logically, sufficient distribution of testing doesn't negate sufficient distribution of evil demons. Practically, if the evil demon has state actor level resources, it is more likely to have sufficient distribution than an ordinary commercial or private interest. On the other hand, I don't think it's really necessary to prove with technology that the 中國人民解放軍 is behind this. Diplomatic logic is sufficient. The behavio…

That's the odd thing, they could jam it instantly if they so chose to. The GFWs primary purpose is to limit access to certain urls from within China. Now of course those repos are intended to circumvent that but once someone has them they are out of reach of the GFW. So blocking those urls at the GFW would seem to be all that's really needed. Tools like these should be accessible from as many places as possible.

Diplomatic logic suggests Github is serving as an object lesson:

  1. 中华人民共和国 has laws.
  2. 中华人民共和国 is well connected to the internet.
  3. 中华人民共和国 can project its interests 
     around the world easily in rather nasty ways.
  4. 中华人民共和国 can project its interests from
     within its borders.
  5. 中华人民共和国 has an interest in controlling
     commerce within its borders.
I believe this is an act of foreign policy, not domestic. It's not about unplugging citizens from the internet. It is about achieving some parity with other state level actors in regard to what is and isn't allowed on the internet.

中华人民共和国 's interests are orthogonal to those of the US and UK. It is not so much interested in the internet as an organ of a surveillance state or as an alternative source of foreign intelligence in lieu of boots on the ground.

The mechanics of the attack are entirely within the realm of sanctioned internet behavior: visiting a site places javascript in the browser without explicit approval of the end user. The javascript may do something not in the user's interest. The javascript may generate unnecessary internet traffic. The purposes for which the javascript does so are solely the purposes of the site injecting it.

The great wall comes with terms and conditions.

Re: Pin-pointing China's attack against GitHub

#78

This is important evidence for our government. It'll be interesting to see how they respond to these attacks -- attacks by a nation state against key United States Internet infrastructure. It seems a bit of a stretch to say that Github is "key US Internet infrastructure"...

If GitHub were down for two days that's a metric shitload of projects that can't get deployed. There's a significant number of software projects with dependencies on Github-hosted stuff.

If github were down for two days, you're probably right, those projects can't be deployed.

But if github were down for two months, the nature of git suggests that deployment for those many individual projects would shift either to the originators' infrastructure, or some other aggregating service.

Re: Pin-pointing China's attack against GitHub

#79

Earlier quoted context omitted.

That's the odd thing, they could jam it instantly if they so chose to. The GFWs primary purpose is to limit access to certain urls from within China. Now of course those repos are intended to circumvent that but once someone has them they are out of reach of the GFW. So blocking those urls at the GFW would seem to be all that's really needed. Tools like these should be accessible from as many places as possible.

Diplomatic logic suggests Github is serving as an object lesson: 1. 中华人民共和国 has laws. 2. 中华人民共和国 is well connected to the internet. 3. 中华人民共和国 can project its interests around the world easily in rather nasty ways. 4. 中华人民共和国 can project its interests from within its borders. 5. 中华人民共和国 has an interest in controlling commerce within its borders. I believe this is an act of foreign policy, not domestic. It's not about…

> The great wall comes with terms and conditions.

I don't consider myself subject to those terms and conditions and attacking github affects me in a very direct way. As such this is not acceptable and I hope that sufficient work will go into un-ambiguously determining who did this.

Re: Pin-pointing China's attack against GitHub

#80

To say that the "Chinese government" is involved I think understates the situation. We know as fact that their army has invested considerable time and money in a cyberwarfare unit. And that the company that operates the Firewall is a military contractor. When Sony was hacked a few months ago, the media couldn't wait to label it a "terrorist act" by North Korea. I just now searched Google News for "github terrorism".…

>But is "terrorism" even the correct word for this? Don't use that word. It's barely even a word any more, its become one of those weaponized magic symbols used for mind control. See also "freedom", "globalization", "sharing", "choice" and so on. Instead, you can just use words like "murder", "destruction of infrastructure" and the like.

Makes sense, once you can come up with a single word to refer to targeting civilians with violence to try to effect political change. That's what "terrorism" meant and that's what it means, even if our news media and government have decided that it can only ever be applied to Muslims.
Post reply on HN