Live data from Hacker News

Pin-pointing China's attack against GitHub

blog.erratasec.com

131–140 of 144 posts

Re: Pin-pointing China's attack against GitHub

#131
post #95

Earlier quoted context omitted.

You can't selectively block content on an SSL connection w/o having a back door to the encryption keys used to secure the connection. A man in the middle attack would be detectable unless the root certificates were compromised.

That's where CNNIC comes in. All they need to do is issue their own fake certificate for (insert blocked site here).

Isn't it wonderful to have your own certificate authority.

Re: Pin-pointing China's attack against GitHub

#132

Earlier quoted context omitted.

Wouldn't financial sanctions hurt the US a lot more than it does China ? I mean they've Tibet for the trump card after all; Cyber-attacks are kid-stuff. (P.S: I sympathize with the Tibetans; but there is really no political will to resolve this, not in the US, not in EU, not in India).

The threat is just as useful as an actual sanction.

Surely the Chinese in all their Wisdom know the futility of these threats ?

Besides, I'm sure it is easy for them to manipulate US senators by giving them campaign funds.

Re: Pin-pointing China's attack against GitHub

#133
post #127
post #94

This mouth-breathing Bullshit really needs to stop. the overwhelmingly most likely suspect for the source of the GitHub attacks is the Chinese government. Why would the "Chinese government" carry out an open attack against an american company for absolutely no potential gain at all? Do you really think they are stupid enough to believe such an attack could remove these two software packages from the internet?

Why would the "Chinese government" carry out pervasive domestic censorship? They know information is still going to get around on back channels. That was never the point. The potential gain is that they can extend this capability (and chilling effect) to GitHub and other sites that aren't under the sovereign control of China. Nobody wants to go out of business just because a user uploaded a file which is politically…

Now every company will think twice and come up with some weaselly reason why they can't have text files about Falun Gong or whatever.

You mean like Github did in this very case? Except wait, they didn't.

So who is this "every company" that will now "think twice"?

Re: Pin-pointing China's attack against GitHub

#134
post #128
post #105

Earlier quoted context omitted.

What chilling effect? Github is up and running after all. Both targeted projects are online: https://github.com/greatfire https://github.com/cn-nytimes Looks like if you want to mess with China then all you have to do is put your material on Github. You think that is the lesson China wanted to teach the world?

GitHub has the protection of the US Government, which has a vested interest in fighting the precedent that Chinese attackers are setting here. Interestingly, this also gives China more bargaining power in its negotiations with the US about "cyber" issues

GitHub has the protection of the US Government, which has a vested interest in fighting the precedent that Chinese attackers are setting here.

Why would the US Government be concerned about "chinese attackers" that apparently can't even take out a civilian top100 website?

Interestingly, this also gives China more bargaining power in its negotiations with the US about "cyber" issues

You mean they will offer to stop "pretend attacking" american companies, and the US will then make concessions out of gratitude?

Re: Pin-pointing China's attack against GitHub

#135

Earlier quoted context omitted.

HTTPS. They can't tell what URL a user is requesting.

> HTTPS. They can't tell what URL a user is requesting. I am sure they have a private key of some of the CAs shipped with major browsers lying around somewhere...

I believe the chinese government actually operates a CA. But it isn't worth it to them to expend such a valuable asset on an operation like that.

Re: Pin-pointing China's attack against GitHub

#136

Earlier quoted context omitted.

I think that action was somewhat different in nature, though. It's an instance of Vogon-type bureaucracy that sends blocking orders to Internet service providers without an understanding of the issues. I presume the Indian government is not actively trying to shut down VPNs that people use to access this kind of resources. In short, I believe the Chinese government knows what it is doing, while the Indian government…

"Vogon-type": that's mind-bogglingly accurate!

By the way, in my career of 25 years of professional software development, I've only once delivered something that was certified to be bug-free.

That was when the company transferred our work, and the test servers, to India. We shipped the machines, and to send them, they had to be packed on pallets. The pallets were wooden. For Indian customs bureaucracy, I had to arrange a paper called phytosanitary certificate, which states that the wood has no bugs.

Re: Pin-pointing China's attack against GitHub

#137

Earlier quoted context omitted.

The Internet has always been weaponized (in the sense that it was designed to be a countermeasure against a nuclear first strike).

That's not true, pure urban legend. http://en.wikipedia.org/wiki/ARPANET#Misconceptions_of_desig... Even if it were true, designing something to withstand attack doesn't make it a weapon. Is a kevlar vest a weapon?

Ah, I didn't know that. But I would call something that can survive a nuclear strike and then be used to coordinate a counter-offensive a weapon, or a least part of a weapon system.

Re: Pin-pointing China's attack against GitHub

#138

Earlier quoted context omitted.

Extremely unlikely. GFW is, ironically, considered "critical infrastructure" and is closely monitored.

Ironically? How is it ironic that a centerpiece of the he Chinese Government's control and monitoring of information is considered critical infrastructure and closely monitored by the Chinese Government?

I was saying "ironic" as this article classifies GitHub as important infrastructure. But anyway I totally agree with you.

Re: Pin-pointing China's attack against GitHub

#139

Earlier quoted context omitted.

Makes sense, once you can come up with a single word to refer to targeting civilians with violence to try to effect political change. That's what "terrorism" meant and that's what it means, even if our news media and government have decided that it can only ever be applied to Muslims.

The problem is, there's no well defined way to tell which version of the word someone's using. That's the point. So best to just not use it. (Obviously you do need to use it sometimes, in an academic context for example. It's a tricky one.)

I've been told by an academic in the field (International Relations) that even within the field there is no academic consensus about the term "terror(ism)".

I'm not sure if that causes the word to be avoided in academic writing, I suppose largely yes (for its lack of any well-defined meaning) with some exceptions (probably by those who agree with the propaganda surrounding the word).

Re: Pin-pointing China's attack against GitHub

#140

Earlier quoted context omitted.

>But is "terrorism" even the correct word for this? Don't use that word. It's barely even a word any more, its become one of those weaponized magic symbols used for mind control. See also "freedom", "globalization", "sharing", "choice" and so on. Instead, you can just use words like "murder", "destruction of infrastructure" and the like.

You forgot 'communism'.

And what about "hackers"? :)
Post reply on HN