Live data from Hacker News

Pin-pointing China's attack against GitHub

blog.erratasec.com

101–110 of 144 posts

Re: Pin-pointing China's attack against GitHub

#101
post #96
post #94

This mouth-breathing Bullshit really needs to stop. the overwhelmingly most likely suspect for the source of the GitHub attacks is the Chinese government. Why would the "Chinese government" carry out an open attack against an american company for absolutely no potential gain at all? Do you really think they are stupid enough to believe such an attack could remove these two software packages from the internet?

What is the diplomatic downside for china exactly? If China can occupy & claim other countries territory in the face of international pressure without a problem, what makes you think a convert op to DDoS github is out of the question?

what makes you think a convert op to DDoS github is out of the question?

The fact that this attack doesn't pass even a most cursory risk/reward analysis.

Anyone with the technical smarts to carry it out must be well aware that there is zero upside potential for China. The targeted projects are not gonna disappear, github is not gonna disappear.

All possible outcomes are negative; The targeted projects get extra media attention (Streisand effect), the "Cyberwar" narrative in the west is fueled (cf. this HN thread), in the worst case there could even be a minor diplomatic quarrel with the US.

What do they have to win here?

Re: Pin-pointing China's attack against GitHub

#102
post #101
post #96

Earlier quoted context omitted.

What is the diplomatic downside for china exactly? If China can occupy & claim other countries territory in the face of international pressure without a problem, what makes you think a convert op to DDoS github is out of the question?

what makes you think a convert op to DDoS github is out of the question? The fact that this attack doesn't pass even a most cursory risk/reward analysis. Anyone with the technical smarts to carry it out must be well aware that there is zero upside potential for China. The targeted projects are not gonna disappear, github is not gonna disappear. All possible outcomes are negative; The targeted projects get extra media…

I see several wins for china, the first one is showing off the offensive power of their "great firewall". Not everyone has the ability to withstand such an attack, the chilling effect is real.

Re: Pin-pointing China's attack against GitHub

#103

To say that the "Chinese government" is involved I think understates the situation. We know as fact that their army has invested considerable time and money in a cyberwarfare unit. And that the company that operates the Firewall is a military contractor. When Sony was hacked a few months ago, the media couldn't wait to label it a "terrorist act" by North Korea. I just now searched Google News for "github terrorism".…

"github terrorism"

the era of a weaponized internet

Is HN turning into Fox News now?

Re: Pin-pointing China's attack against GitHub

#104

Earlier quoted context omitted.

> The great wall comes with terms and conditions. I don't consider myself subject to those terms and conditions and attacking github affects me in a very direct way. As such this is not acceptable and I hope that sufficient work will go into un-ambiguously determining who did this.

Github is a commercial interest. 中华人民共和国 has in recent years worked with commercial interests to mutually acceptable solutions. From 中华人民共和国's standpoint, what the internet's surfs want is Github's concern and they can make their business decisions accordingly. Consider it a DCMA takedown notice.

Why do you use '中华人民共和国' instead of China?

Re: Pin-pointing China's attack against GitHub

#105
post #101

Earlier quoted context omitted.

what makes you think a convert op to DDoS github is out of the question? The fact that this attack doesn't pass even a most cursory risk/reward analysis. Anyone with the technical smarts to carry it out must be well aware that there is zero upside potential for China. The targeted projects are not gonna disappear, github is not gonna disappear. All possible outcomes are negative; The targeted projects get extra media…

I see several wins for china, the first one is showing off the offensive power of their "great firewall". Not everyone has the ability to withstand such an attack, the chilling effect is real.

What chilling effect?

Github is up and running after all. Both targeted projects are online:

  https://github.com/greatfire
  https://github.com/cn-nytimes
Looks like if you want to mess with China then all you have to do is put your material on Github. You think that is the lesson China wanted to teach the world?

Re: Pin-pointing China's attack against GitHub

#106

To say that the "Chinese government" is involved I think understates the situation. We know as fact that their army has invested considerable time and money in a cyberwarfare unit. And that the company that operates the Firewall is a military contractor. When Sony was hacked a few months ago, the media couldn't wait to label it a "terrorist act" by North Korea. I just now searched Google News for "github terrorism".…

The Internet has always been weaponized (in the sense that it was designed to be a countermeasure against a nuclear first strike).

Re: Pin-pointing China's attack against GitHub

#107
post #105

Earlier quoted context omitted.

I see several wins for china, the first one is showing off the offensive power of their "great firewall". Not everyone has the ability to withstand such an attack, the chilling effect is real.

What chilling effect? Github is up and running after all. Both targeted projects are online: https://github.com/greatfire https://github.com/cn-nytimes Looks like if you want to mess with China then all you have to do is put your material on Github. You think that is the lesson China wanted to teach the world?

You dont see a chilling effect when the choice is either host your content on github or be blasted off the internet?

Lets not forget this wasnt an easy thing for github to handle. Their service still isnt running at 100% normal. Not to mention the cost burden they're currently dealing with.

Re: Pin-pointing China's attack against GitHub

#108

Earlier quoted context omitted.

> The great wall comes with terms and conditions. I don't consider myself subject to those terms and conditions and attacking github affects me in a very direct way. As such this is not acceptable and I hope that sufficient work will go into un-ambiguously determining who did this.

Github is a commercial interest. 中华人民共和国 has in recent years worked with commercial interests to mutually acceptable solutions. From 中华人民共和国's standpoint, what the internet's surfs want is Github's concern and they can make their business decisions accordingly. Consider it a DCMA takedown notice.

I haven't read all your posts, but it seems like you've spent some time in China. You articulate matters as I'd expect a mainlander Chinese to do so, eg Western governments, or "sovereigns" as you say, restricting freedoms to maintain a harmonious society.

Re: Pin-pointing China's attack against GitHub

#109
post #8

While this is a very interesting read (learned a thing or two), the author's conclusion is a bit suspect. Using my custom http-traceroute, I've proven that the man-in-the-middle machine attacking GitHub is located on or near the Great Firewall of China. Although suspicious, it seems one would need to know a lot more about China Unicom and their infrastructure to say this conclusively.

I think the thing everyone is forgetting is that if it isn't state sponsored/approved then why hasn't it been turned off (as far as I am aware the attack is still ongoing). If it was a hack, surely China Unicom should have fixed it by now?

Hasn't it stopped as of March 31? Github system status now shows green, whereas they previously said "We will keep our status at yellow until the threat has subsided": https://status.github.com/messages

Re: Pin-pointing China's attack against GitHub

#110

Earlier quoted context omitted.

Github is a commercial interest. 中华人民共和国 has in recent years worked with commercial interests to mutually acceptable solutions. From 中华人民共和国's standpoint, what the internet's surfs want is Github's concern and they can make their business decisions accordingly. Consider it a DCMA takedown notice.

Why do you use '中华人民共和国' instead of China?

Besides being batshit crazy?

For the same reason I use "Github" instead of saying "distributed version control ddos'ed" or "git unavailable on the internet". It picks out a more precise set of attributes and methods and limits the likelihood of slipping into anthropomorphisms such as "The Chinese." In particular it limits the range of what is historically relevant: ground combat against the US Army in the 1950's is, against the USMC in 1900 not so much.

Since I believe this is a matter of foreign policy and international trade, the sovereign and the corporation are the appropriate level of abstraction for analysis and language should reflect that in order to be clear.

Was it the 中國人民解放軍 or the 中华人民共和国?

Post reply on HN