Live data from Hacker News

Pin-pointing China's attack against GitHub

blog.erratasec.com

111–120 of 144 posts

Re: Pin-pointing China's attack against GitHub

#111

Earlier quoted context omitted.

Not terrorism. The attack was somewhat narrowly targeted (at least as narrowly as technically possible, given it's all on one domain) and also tried to achieve the desired end goal. They weren't blowing up random parts of github infrastructure.

I wonder if the same terminology would have been used if Iran or North Korea had conclusively perpetrated this attack.

I have no question there's a political aspect, though calling the Sony attack terrorism is a better fit. Assuming the purported objective was to prevent release of The Interview, how does exposing the alias Tom Hanks uses to check in to hotels accomplish that? How does that accomplish any objective? (Regardless of the responsible party.)

Re: Pin-pointing China's attack against GitHub

#114

Earlier quoted context omitted.

Github is a commercial interest. 中华人民共和国 has in recent years worked with commercial interests to mutually acceptable solutions. From 中华人民共和国's standpoint, what the internet's surfs want is Github's concern and they can make their business decisions accordingly. Consider it a DCMA takedown notice.

I haven't read all your posts, but it seems like you've spent some time in China. You articulate matters as I'd expect a mainlander Chinese to do so, eg Western governments, or "sovereigns" as you say, restricting freedoms to maintain a harmonious society.

Never been near to China. I read some Hobbes. Thinking about sovereignty helps me referee futball matches. On the one hand in terms of foul selection and its change during the course of a match, on the other hand the abstraction of a Leviathan with six eyes, two flags and a whistle is a useful theme for the crew pregame regarding roles, responsibilities and expectations.

That Hobbes underpins pretty much any political discussion in the Anglophone world even if not explicitly acknowledged is just a bonus, and I use the terms in the sense of "is" not "ought".

That the Hobbesian model maps onto the political traditions of the Middle Kingdom and futball with little friction suggests the pervasiveness and universality of little '\p` politics.

Re: Pin-pointing China's attack against GitHub

#115
post #2

That's cool, I didn't know how traceroutes work. Is he planning on releasing the http traceroute tool?

Here ya go: https://github.com/robertdavidgraham/masscan @collinrm I just took masscan, changed the HTTP request, then tweeked the code to generate a small TTL. Source: https://twitter.com/ErrataRob/status/583433175302479872

On OSX, it's available via Homebrew, brew install masscan

Re: Pin-pointing China's attack against GitHub

#116
post #81

"blocking GitHub is not really a viable option" he said. Tell that to the world's craziest democracy - India, which banned GitHub, Vimeo, Pastebin and a bunch of others in December last year. Some bans were lifted later. Source : http://www.zdnet.com/article/india-blocks-32-websites-includ...

Agree with this. Anyone who thinks blocking GitHub is not really a viable option has never been on the other side of the GFW. The Chinese government will happily block any site they want to and they have little/no regard for the popularity or usefulness of the site in question, and often they will block popular foreign sites to help copycat local versions thrive. Off the top of my head they block Facebook, Twitter an…

github is no where near "popular" in china...

Re: Pin-pointing China's attack against GitHub

#117

I don't get it. Why doesn't GFW just block those github pages in particular? A lot of people can fork these repos but they won't be anywhere popular to the current pages.

HTTPS. They can't tell what URL a user is requesting.

> HTTPS. They can't tell what URL a user is requesting.

I am sure they have a private key of some of the CAs shipped with major browsers lying around somewhere...

Re: Pin-pointing China's attack against GitHub

#118
post #95
post #81

Earlier quoted context omitted.

Agree with this. Anyone who thinks blocking GitHub is not really a viable option has never been on the other side of the GFW. The Chinese government will happily block any site they want to and they have little/no regard for the popularity or usefulness of the site in question, and often they will block popular foreign sites to help copycat local versions thrive. Off the top of my head they block Facebook, Twitter an…

You can't selectively block content on an SSL connection w/o having a back door to the encryption keys used to secure the connection. A man in the middle attack would be detectable unless the root certificates were compromised.

That's where CNNIC comes in. All they need to do is issue their own fake certificate for (insert blocked site here).

Re: Pin-pointing China's attack against GitHub

#119

To say that the "Chinese government" is involved I think understates the situation. We know as fact that their army has invested considerable time and money in a cyberwarfare unit. And that the company that operates the Firewall is a military contractor. When Sony was hacked a few months ago, the media couldn't wait to label it a "terrorist act" by North Korea. I just now searched Google News for "github terrorism".…

The Internet has always been weaponized (in the sense that it was designed to be a countermeasure against a nuclear first strike).

That's not true, pure urban legend.

http://en.wikipedia.org/wiki/ARPANET#Misconceptions_of_desig...

Even if it were true, designing something to withstand attack doesn't make it a weapon. Is a kevlar vest a weapon?

Re: Pin-pointing China's attack against GitHub

#120

Earlier quoted context omitted.

Makes sense, once you can come up with a single word to refer to targeting civilians with violence to try to effect political change. That's what "terrorism" meant and that's what it means, even if our news media and government have decided that it can only ever be applied to Muslims.

The problem is, there's no well defined way to tell which version of the word someone's using. That's the point. So best to just not use it. (Obviously you do need to use it sometimes, in an academic context for example. It's a tricky one.)

I fall on different sides of where it makes sense to use the word, but you're right: it is hard to tell how someone uses it.
Post reply on HN