Earlier quoted context omitted.
Most of it comes down to shoving 10X traffic down a 1X pipe. You can write smart fast software, but if your wires are saturated... There is one common problem, and that is that the major transit carriers/ISPs allow you to spoof your source IP. That allows some attacks to be done easier than otherwise. But that's more of a special case and doesn't matter when there is hijacking going on like in this attack. Blocking a…
If it were possible to stop some of that 10X before it even got to the pipe, would be the only kind of mitigation for that kind of attack. For something like that though, would require some pretty sophisticated firewall technology that lives outside of your infrastructure.
GitHub under ongoing DDoS attack
291–300 of 352 posts
Re: GitHub under ongoing DDoS attack
#292Earlier quoted context omitted.
If the PRC were merely snooping, and not actively attacking, that equivalence would work. I was also under the impression that this is already in violation of treaty, the only saving grace for the PRC being that it hasn't been proven it's them.
Well if it isn't proven it's them, just let's not assume guilty, right?
Re: GitHub under ongoing DDoS attack
#293The PRC's DDoS of GitHub seems a little risky.[1] If GitHub is inventive (or desperate) enough, they could call on their users for aid. The perpetrators would immediately draw the ire of vast numbers of talented programmers. And GitHub is positioned to direct this ire toward useful ends. They could encourage users to contribute to GreatFire, or even start other initiatives and projects to stymie censorship. The outco…
Looks to me like it's time for a DDoS X-Prize. 1. SSDP Flood 21% 2. SYN Flood 19% 3. UDP Flood 13% 4. UDP Fragment 12% 5. NTP Flood 8% 6. GET Flood 7% 7. CharGEN Attack 5% 8. DNS Flood 5% 9. ICMP Flood 2% 10. SNMP Flood 2% Eliminating these 10 attack vectors would account for 94% of DDoS attacks according to this visualization[1], as witnessed by Akamai over the last 30 days. Just the top 3 is more than 50%. Seems li…
Let's say your pipe can receive 1 Liter per second of water. There are some impurities that you can filter through your faucet, this is analogous to the software firewall. However what happens when someone starts piping 99 L/s of sludge through the other end? No matter how sophisticated the filter you have on your faucet, the water you will get out of it is going to slow to a trickle.
Now I can already hear you asking, why does the Internet allow people to send whatever sludge they want? And the answer is because that's the way the internet is made. There has been a push to stop spoofing called BCP38, but this requires EVERYONE to do extra work and spend extra money which is why relatively little progress has been made since it was released 15 years ago, and is likely to never succeed.
If it was as easy as creating a piece of software to deal with, large businesses like Prolexic wouldn't be banking their future on a problem that would be so easily solved.
Re: GitHub under ongoing DDoS attack
#294Hi, foreigner working in Chinese high tech company here. I wonder a bit, on which ground is this attack attributed to Chinese gov? It looks a bit unlikely to me. China has some cyber military but they are more likely to be pragmatic and choose wisely their targets. There's a bunch of script kiddies but they would choose also something else. However it seems possible that many servers hosted in China are not secured a…
> China has some cyber military... China has approximately 2 million people in its 'cyber army'. Not all of them are going to be experts, but sheer volume makes them probably the most effective 'cyber army' out there.
Re: GitHub under ongoing DDoS attack
#295Earlier quoted context omitted.
"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.
We should never take up arms for a thread that has no human casualties, especially when there are alternatives. If your neighbour enter your home uninvited, because the door is not locked, the first thing you do is ask nicely not to do that. The next thing you do is lock the door. You don't start shooting at them first ...
Re: GitHub under ongoing DDoS attack
#296Earlier quoted context omitted.
I don't think banning countries from the Internet is the answer, but net neutrality seems like a completely separate issue.
So because the Chinese government are being hostile, all the chinese companies innocently doing their own business should have their comms cut off as well? Chinese families should not be able to contact their travelling members? This is definitively the exact same issue - the Chinese government is not the only entity to use the Chinese intertubes.
Re: GitHub under ongoing DDoS attack
#297Earlier quoted context omitted.
What is the PRC's problem with Github?
Its due to these two repost most likely. https://github.com/greatfire/ https://github.com/cn-nytimes/ Access to them is currently no possible though.
Re: GitHub under ongoing DDoS attack
#298Re: GitHub under ongoing DDoS attack
#299As a paying customer of Github I want them to know they have my undivided support in staying strong against "the bullies".
And paying Github as a business is a no-brainer.
Re: GitHub under ongoing DDoS attack
#300Earlier quoted context omitted.
Looks to me like it's time for a DDoS X-Prize. 1. SSDP Flood 21% 2. SYN Flood 19% 3. UDP Flood 13% 4. UDP Fragment 12% 5. NTP Flood 8% 6. GET Flood 7% 7. CharGEN Attack 5% 8. DNS Flood 5% 9. ICMP Flood 2% 10. SNMP Flood 2% Eliminating these 10 attack vectors would account for 94% of DDoS attacks according to this visualization[1], as witnessed by Akamai over the last 30 days. Just the top 3 is more than 50%. Seems li…
You aren't going to make ddos attacks go away by offering prizes for a miracle software solution. It amazes me that there are so many programmers here who don't understand this basic principal. I think the only way we can get people to understand the situation is with an analogy. Let's say your pipe can receive 1 Liter per second of water. There are some impurities that you can filter through your faucet, this is ana…
Do you know how X-Prizes work?
Hit: Did I say anything about software?
[edit: It's odd to me that this would get down voted. Is it offensive? Or are downvoters really that opposed to thinking outside of the box?
The X-Prize encourages participation from unexpected directions, precisely where innovation is often found. As the parent post demonstrates (almost as if on queue), it's quite common for skilled experts within a field to become overly focused on specific classes of solution. I was careful not to say anything about how the above goals might be achieved.]