Live data from Hacker News

Pin-pointing China's attack against GitHub

blog.erratasec.com

51–60 of 144 posts

Re: Pin-pointing China's attack against GitHub

#51

To say that the "Chinese government" is involved I think understates the situation. We know as fact that their army has invested considerable time and money in a cyberwarfare unit. And that the company that operates the Firewall is a military contractor. When Sony was hacked a few months ago, the media couldn't wait to label it a "terrorist act" by North Korea. I just now searched Google News for "github terrorism".…

With any meaningful definition of the word neither the github attack nor the Sony hack was terrorism. Nobody was trying to spread terror among civilians, nobody tried to influence government policy.

Re: Pin-pointing China's attack against GitHub

#52

China is the second most powerful country in the world. Do people really think they are that stupid ? They are not going to attack an American company using infrastructure that anyone can track back to them. This Github DDoS has got to be the work of someone trying to frame the Chinese government. Has anyone considered that angle ?

> Do people really think they are that stupid ? That's not really a defence. They could easily be that stupid, bureaucracies tend to do extremely stupid stuff when looked at from the outside but every cog on the inside thinks that its action makes perfect sense. > This Github DDoS has got to be the work of someone trying to frame the Chinese government. Evidence? > Has anyone considered that angle ? Sure, but so far…

> bureaucracies tend to do extremely stupid stuff when looked at from the outside but every cog on the inside thinks that its action makes perfect sense.

If this is Chinese doing, the likely ones responsible are the Chinese Intelligence, not their bureaucracy.

> Evidence?

Occam's Razor. I find it hard to believe that a society with sufficient level of sophistication to obtain $9 trillion GDP[1] would 'accidentally' go on to declare cyber war on US. Especially considering the fact that the attack itself was pretty sophisticated.

[1] http://en.wikipedia.org/wiki/List_of_countries_by_GDP_%28nom...

Re: Pin-pointing China's attack against GitHub

#53

China is the second most powerful country in the world. Do people really think they are that stupid ? They are not going to attack an American company using infrastructure that anyone can track back to them. This Github DDoS has got to be the work of someone trying to frame the Chinese government. Has anyone considered that angle ?

Powerful countries doing a show of force is nothing unusual. They know they can get away with it. If they had severely impacted github it would have sent a strong message not to do buisiness with people who circumvent the Great Firewall. It makes complete sense to me, they just failed.

On the other hand, why would anybody go to this length to frame to Chinese government? What would they try to accomplish? Obama sending a strongly worded letter to the Chinese government?

Re: Pin-pointing China's attack against GitHub

#54

China is the second most powerful country in the world. Do people really think they are that stupid ? They are not going to attack an American company using infrastructure that anyone can track back to them. This Github DDoS has got to be the work of someone trying to frame the Chinese government. Has anyone considered that angle ?

The problem with that kind of speculation is you can equally use the same argument against itself. ie maybe they're bluffing people into thinking that the Chinese military / government have been framed as it seems too obvious that it would have been them.

We could also speculate from the angle that the officers in charge of making these decisions are not tech-savvy themselves (or at least not to the level that they might realise just how traceable these attacks), which isn't a huge assumption to make when you look at how incompetent many government officials are who have serious influence over technology policies (eg http://www.bbc.co.uk/news/technology-23437473)

So anyway, my point is it's better to look for a little evidence to support a hypothesis rather than blindly speculate.

Re: Pin-pointing China's attack against GitHub

#55

Earlier quoted context omitted.

The man in the middle attack was injecting javascript to recruit unwitting man on the side attackers against github. github was not being MITM'd, but its "attackers" were. edit: above may be imprecise. I went back and read the original more closely. they note that if they artificially drop an injected packet, it doesn't get resent (and hence the conclusion that it's man on the side), but they don't mention whether th…

Yes, I was wondering whether the original packets arrive or not as well. I'd love to see the traces. In my quick read of the this article I couldn't understand the method that they used to make their determination. Was it the bad packets or the good packets that had the TTL rewritten? The fact that there is a system rewriting packets does not necessarily imply it is an attack. I once wrote a SIP client and the local…

Responding to my own post (bad form). But hasn't he just found a network cache? Many firewalls block certain kinds of ICMP traffic for security reasons. So not being able to traceroute to some place is not suspicious in and of itself. So he sets the TTL so that it should not hit Baidu, but I notice in the picture of the last trace that he actually gets a "200 OK". I would not have thought that a man in the middle device would respond because then it would have to also know the content with which to respond. Since this is not the target Baidu machine, this has to be a cache.

It is possible that the cache is also injecting the attack, but I don't actually see anything that suggests this from the data in the article.

Re: Pin-pointing China's attack against GitHub

#56

Earlier quoted context omitted.

> Do people really think they are that stupid ? That's not really a defence. They could easily be that stupid, bureaucracies tend to do extremely stupid stuff when looked at from the outside but every cog on the inside thinks that its action makes perfect sense. > This Github DDoS has got to be the work of someone trying to frame the Chinese government. Evidence? > Has anyone considered that angle ? Sure, but so far…

> bureaucracies tend to do extremely stupid stuff when looked at from the outside but every cog on the inside thinks that its action makes perfect sense. If this is Chinese doing, the likely ones responsible are the Chinese Intelligence, not their bureaucracy. > Evidence? Occam's Razor. I find it hard to believe that a society with sufficient level of sophistication to obtain $9 trillion GDP[1] would 'accidentally' g…

> the Chinese Intelligence, not their bureaucracy.

Intelligence agencies are bureaucracies. Some are more efficient (less wasteful) than others, but in the end, intelligence work is seldom about secret agents driving Aston Martins. Most of it has always been paperwork. Paperwork is nowadays in electronic format. I don't think the Chinese intelligence agencies are an exception.

Re: Pin-pointing China's attack against GitHub

#57
post #46

Earlier quoted context omitted.

No and there probably won't be. Them publicly saying they were being attacked by the Chinese government would put them on some seriously questionable legal ground. They definitely went the right route by not saying anything.

Which laws would they be violating by announcing they were attacked by China?

A number of Chinese laws, or executive orders or whatever, actually might be violated.

Re: Pin-pointing China's attack against GitHub

#58

"blocking GitHub is not really a viable option" he said. Tell that to the world's craziest democracy - India, which banned GitHub, Vimeo, Pastebin and a bunch of others in December last year. Some bans were lifted later. Source : http://www.zdnet.com/article/india-blocks-32-websites-includ...

Only Gist was blocked, not Github. It was a knee-jerk reaction to a court order after ISIS made a series of threats and some Indians were found to be in contact with the ISIS. All those sites were unblocked soon after.

Re: Pin-pointing China's attack against GitHub

#59
In the end, I wonder if the purpose of the great firewall is not for China to defend itself against foreign cyber attacks or because "free internet" might not benefit China currently.

I'm sure computers are now mainstream enough that it would matter for any country to put cyber warfare as a key strategy. The US and the west dominate through open trade and easy communications and free speech. Maybe that makes China vulnerable, and they're trying to defend themselves economically.

You can accuse China all you want, but if you're an american, it's harder to listen to those accusations.

Re: Pin-pointing China's attack against GitHub

#60
post #8

While this is a very interesting read (learned a thing or two), the author's conclusion is a bit suspect. Using my custom http-traceroute, I've proven that the man-in-the-middle machine attacking GitHub is located on or near the Great Firewall of China. Although suspicious, it seems one would need to know a lot more about China Unicom and their infrastructure to say this conclusively.

My first thought was that at the very least he should be comparing it to a tcp-traceroute (i.e. traceroute -T ...) rather than an ICMP one. Other routers before them may make different routing decisions based upon the type of IP traffic, so assuming both take the same path is unsafe.
Post reply on HN