Live data from Hacker News

Pin-pointing China's attack against GitHub

blog.erratasec.com

61–70 of 144 posts

Re: Pin-pointing China's attack against GitHub

#61
post #38
post #25

Earlier quoted context omitted.

> It seems to me that we have officially entered the era of a weaponized internet. Couldn't agree more. And GFW is indeed a WMD that must be stopped.

... I can't tell if this is sarcasm or serious. But seriously... What "Mass destruction" can the GFW cause? ... Like Amazon/Azure/Rackspace are WMDs under your current definition?

Mass destruction of freedom of access to Western academic research, journalism and social ties.

Re: Pin-pointing China's attack against GitHub

#63
post #8

While this is a very interesting read (learned a thing or two), the author's conclusion is a bit suspect. Using my custom http-traceroute, I've proven that the man-in-the-middle machine attacking GitHub is located on or near the Great Firewall of China. Although suspicious, it seems one would need to know a lot more about China Unicom and their infrastructure to say this conclusively.

I think the thing everyone is forgetting is that if it isn't state sponsored/approved then why hasn't it been turned off (as far as I am aware the attack is still ongoing).

If it was a hack, surely China Unicom should have fixed it by now?

Re: Pin-pointing China's attack against GitHub

#64
Is this April fool joke? Or are you guys really taking this whole Chinese government theory seriously? If you were leading a 1.6bn populated country how much you would care about a programmer's code site?

To give all those conspiracy theorists a clear picture, what really happened is merely the scale of problem you have never worked on or dreamed to be working on outside China.

This happened year ago when a Chinese state funded train ticket booking website accidentally deployed to production with a opensourced Javascript vendor file still linked to github. And first day that site went live, 30 billion visitors tried to secure a ticket for coming Chinese New Year, when took down github for a good while. Yes it was a DDOS attack from China, by train ticket buyers.

Last November, Chinese online c2c marketplace TaoBao.com, saw 16.7bn transactions in one day, with more than 1 billion CNY settled in a minute. If any of the web dev responsible for even a small promotion page left a link of cool jquery plugin from GitHub, you could have written another holy crap evil government attack post here.

Re: Pin-pointing China's attack against GitHub

#65

To say that the "Chinese government" is involved I think understates the situation. We know as fact that their army has invested considerable time and money in a cyberwarfare unit. And that the company that operates the Firewall is a military contractor. When Sony was hacked a few months ago, the media couldn't wait to label it a "terrorist act" by North Korea. I just now searched Google News for "github terrorism".…

>>have officially entered the era of a weaponized internet.

Nope, the State department has yet to respond.

Re: Pin-pointing China's attack against GitHub

#66

To say that the "Chinese government" is involved I think understates the situation. We know as fact that their army has invested considerable time and money in a cyberwarfare unit. And that the company that operates the Firewall is a military contractor. When Sony was hacked a few months ago, the media couldn't wait to label it a "terrorist act" by North Korea. I just now searched Google News for "github terrorism".…

Not terrorism. The attack was somewhat narrowly targeted (at least as narrowly as technically possible, given it's all on one domain) and also tried to achieve the desired end goal. They weren't blowing up random parts of github infrastructure.

I wonder if the same terminology would have been used if Iran or North Korea had conclusively perpetrated this attack.

Re: Pin-pointing China's attack against GitHub

#67

Earlier quoted context omitted.

> Do people really think they are that stupid ? That's not really a defence. They could easily be that stupid, bureaucracies tend to do extremely stupid stuff when looked at from the outside but every cog on the inside thinks that its action makes perfect sense. > This Github DDoS has got to be the work of someone trying to frame the Chinese government. Evidence? > Has anyone considered that angle ? Sure, but so far…

> bureaucracies tend to do extremely stupid stuff when looked at from the outside but every cog on the inside thinks that its action makes perfect sense. If this is Chinese doing, the likely ones responsible are the Chinese Intelligence, not their bureaucracy. > Evidence? Occam's Razor. I find it hard to believe that a society with sufficient level of sophistication to obtain $9 trillion GDP[1] would 'accidentally' g…

I question your invocation of Occam's Razor here. Between:

1) the attack is perpetrated by the entity the evidence suggests and

2) the attack was prepetrated by another entity who cleverly used infrastructure of the first entity to frame them for it,

applying Occam's Razor would suggest situation #1 in lieu of evidence to the contrary.

Re: Pin-pointing China's attack against GitHub

#68
post #23

I have a question with the method, hypothetically, if I am the attacker, I know the ttls of each packets tha tis passing through, right? So when I get a packet with ttl so small that won't survive long enough to reach the target, instead of altering, I just leave it along. So the probe will never know where I am in the route.

But upstream providers within the TTL range will. And during a DDoS like this you can bet that everybody in the chain that is on the good side is in constant communication.

A sufficiently sophisticated man in the middle can be anywhere between origin and destination and have arbitrary distribution. Proving that a particular node is responsible for a particular alteration requires using a trusted trust computer to send packets into the great wall on their first hop.

The experiment in the article required trusted trust of packets destined for the great wall passing through US infrastructure. That this infrastructure can generally be considered neutral is no guarantee that it was in this case. Any router or switch can use arbitrary tables and conditional logic on any packet. The purpose of the experiment was prosecuting a particular suspect not arm's length analysis.

Re: Pin-pointing China's attack against GitHub

#69

Earlier quoted context omitted.

But upstream providers within the TTL range will. And during a DDoS like this you can bet that everybody in the chain that is on the good side is in constant communication.

A sufficiently sophisticated man in the middle can be anywhere between origin and destination and have arbitrary distribution. Proving that a particular node is responsible for a particular alteration requires using a trusted trust computer to send packets into the great wall on their first hop. The experiment in the article required trusted trust of packets destined for the great wall passing through US infrastructu…

So that experiment would need to be repeated in a distributed manner from as many points of origin as possible.

A friend of mine runs a honeypot service that uses servers all around the planet, someone like him would be in a good position to run analysis like this.

Re: Pin-pointing China's attack against GitHub

#70
post #59

In the end, I wonder if the purpose of the great firewall is not for China to defend itself against foreign cyber attacks or because "free internet" might not benefit China currently. I'm sure computers are now mainstream enough that it would matter for any country to put cyber warfare as a key strategy. The US and the west dominate through open trade and easy communications and free speech. Maybe that makes China vu…

The US spent more than 50 years protecting its residents from Cuban sugar and Cuban cigars and sunburns on Cuba's beaches. Such are the absurdities of powerful sovereigns.
Post reply on HN