Live data from Hacker News

GitHub under ongoing DDoS attack

status.github.com

341–350 of 352 posts

Re: GitHub under ongoing DDoS attack

#341
post #259

Earlier quoted context omitted.

> We don't allow foreign raiding parties to enter our country to loot private businesses. Really? The US government does just that, by mass spying of telecommunications.

Both are unethical, but there is a difference between spying (sitting with some binoculars by a window, or snooping around inside the building) and destructive actions (blowing up the entrance with a constant stream of TNT so no one else can get in). US does the former, China does both.

[Citation needed]

We've been hearing propaganda for ages about China & Russia doing evil things in the cyberspace and USA promoting freedoms and such but the NSA revelations among other things have shown that USA is just as guilty of all the spying, attacks, weakening of hardware and software even if it hurts american companies, economic espionage (which was also a difference people here used to make with China and was proven false), etc.

And I'm not even touching Stuxnet and Flame.

> The US generally does not engage in destructive actions with the intent of restricting the rights of their own citizens... just other country's citizens. China does both. Both are very bad, but I think the US still has a slight moral highground here.

If it does. It's not much higher. You're completely restricted in your rights to do anything that the government finds a matter of "national security". Even if it's not related to any official entity [1]

It's time we stop thinking about Us vs Them and who is winning or has a moral high-ground and start thinking in terms of citizens of the world united against injustice.

Opposing attacks like the Chinese against GitHub and the surveillance, propaganda and violence of all the other big powers.

Feeling good about "our side" being slightly better (Subjective and irrational) won't change the fact that it's still unacceptable.

[1] https://firstlook.org/theintercept/2015/03/26/new-low-obama-...

Re: GitHub under ongoing DDoS attack

#342
post #130
post #21

As a paying customer of Github I want them to know they have my undivided support in staying strong against "the bullies".

"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.

> GitHub should get the full support of federal law enforcement, if not the military.

With a few exceptions, the US military has atrocious "cyber" readiness and capability. This isn't yet in their wheelhouse, and any public assistance they might provide would just be risking embarrassment.

Re: GitHub under ongoing DDoS attack

#343

Earlier quoted context omitted.

>Did I say anything about software? Well, you did say: "Who'd like to sponsor? Or should I just spin up a GitHub repo for the code and a kickstarter for the prize money?"

Indeed I did, still no software implication. I was being fairly deliberate about that. What I'm confused about is what the argument is. Is it we shouldn't try to find a solution? I'm sorry if I was unclear that I did not intend to limit the scope of solutions to software, but frankly so what even if I had? In any case the X-Prize proposal seems quite popular so I'd be happy to set it up, help someone else set it up o…

Please stop defending yourself , accept what other know what they talking please.

You cannot setup a github repo for that.

Re: GitHub under ongoing DDoS attack

#344

Earlier quoted context omitted.

Both are unethical, but there is a difference between spying (sitting with some binoculars by a window, or snooping around inside the building) and destructive actions (blowing up the entrance with a constant stream of TNT so no one else can get in). US does the former, China does both.

[Citation needed] We've been hearing propaganda for ages about China & Russia doing evil things in the cyberspace and USA promoting freedoms and such but the NSA revelations among other things have shown that USA is just as guilty of all the spying, attacks, weakening of hardware and software even if it hurts american companies, economic espionage (which was also a difference people here used to make with China and w…

I do pretty much agree with all your points. The revelation that NSA was engaged in economic spying definitely brought their moral highground way down to earth, even if the nature of the spying was somewhat more geopolitical than what China was doing (going after national energy companies, in NSA's case). But a few caveats:

>You're completely restricted in your rights to do anything that the government finds a matter of "national security". Even if it's not related to any official entity [1]

There are very few countries where this is not the case, even supposed extremely liberal countries like the Nordic ones. State secrets and national security are always going to be a monolith hanging over us for centuries. What needs to improve is the internal regulations and auditing behind these processes, to ensure strict adhere to public (not classified) laws and regulations.

I am not nationalistic or even patriotic in the least. I don't like a lot of what the US government and intelligence community does. However, I do see it as the lesser evil when you compare other superpowers like Russia and China.

Re: GitHub under ongoing DDoS attack

#345
post #156

Earlier quoted context omitted.

It's not flatly wrong. I might not have lived in and researched China for 28 years, but I'm not exactly a stranger to the place and have spent the better part of a decade in China and the greater China area and have been circumventing the great firewall for almost 15 years. Unless your China research has been limited to something like the tea cultivating habits of the Bulang minority, you should be able to list off t…

If the PRC solution was blocking the project pages, then Chinese users could just fork clones to circumvent the block. Forcing foreign organizations to anticipate some cost in supporting anti-censorship software is precisely about controlling their own citizens. Your personal attacks do nothing to support your argument. The use of these tools, at large, by the Chinese people may not be what the attack is about. It co…

The GFW is advanced enough to do automated blocking based on content. People could keep forking and those projects would keep getting blocked automatically.

Yes you could change wording up, but then you run the risk of either obfuscating it too much that users of the program don't how to find it, or the government updating filters to block the changes content also.

Groups with real desire to circumvent the GFW have other ways to do it. I've been use ssh tunnelling for almost 15 years without major issues.

Re: GitHub under ongoing DDoS attack

#346
post #153

Hi, foreigner working in Chinese high tech company here. I wonder a bit, on which ground is this attack attributed to Chinese gov? It looks a bit unlikely to me. China has some cyber military but they are more likely to be pragmatic and choose wisely their targets. There's a bunch of script kiddies but they would choose also something else. However it seems possible that many servers hosted in China are not secured a…

The MITM on HTTPS traffic that seems to be involved in the first attack stages is actually pretty good evidence.

If there is a MITM on https then browsers need to untrust those certs.

Re: GitHub under ongoing DDoS attack

#347

Earlier quoted context omitted.

I didn't downvote you but I can see why they did. The way you act is similar to someone running a contest to disprove Turing's proof on the halting problem. If your bandwidth is being filled from the other end, it doesn't matter how sophisticated the filter is at your server. Even if it is theoretically perfect and able to tell which packets came from real requests with 100% accuracy, it will not solve the problem. T…

I understand your position, and I don't want to be offensive. I simply want to be clear. The X-Prize is intended precisely for this type of industry stagnation, and has been very successful at that goal so far. Winners solve unbelievable problems in unbelievable ways. I am, if not an expert, nearly so, and I can say that my first thought is not better filtration. As you rightly point out that is a very hard problem,…

Everything you've suggested requires all networks to cooperate/spend extra time and money, or that no one makes an exploitable protocol in the future (as likely as humans never making mistakes). If you can already get all networks to cooperate/spend extra time and money, then you can make them do BCP38 which would be a more complete solution.

> In addition to your mistaken impression of my inexperience in the filed you are also mistaken that the information I posted is "off a random website". The information is from Akamai's State of the Internet site and represents Akamai's "real-time 24-hour global attack data: sources, targets, and types of attacks". It is linked to directly from Prolexic's home page. Though, I'm sure as an expert you knew that.

And all of this doesn't disprove anything I said.

That website is a marketing piece made for laymen such as yourself.

The fact that you are categorizing those attack vectors as seperate problems instead of being in the same class proves what I claim.

Re: GitHub under ongoing DDoS attack

#348

Earlier quoted context omitted.

If you host your code on this "free" service and you cause a DDos because someone doesn't like what you are doing, are you going to pay for the mitigation costs to the free provider?

Why would I? That someone should pay. What you seem to suggest is DDoS victim blaming :P

When you do something that causes me problems, and you aren't willing to accept the costs, then yea, I'm going to blame you.
Post reply on HN