13 ms·
GitHub under DDoS attack right now (again...)
- cvburgess 13y agoThis is getting ridiculous. There are so many sites to attack, why Github?
- valevk 13y agoMaybe some "corporations" are getting "harmed" because there is so much free code around, and they don't like that. I don't know...
- taspeotis 13y agoWell if your competitor used GitHub for (source control|issue tracking|deploying from a GitHub repository) you could DDoS GitHub (bit of colatoral here and there) for some illegitimate advantage.
- skylan_q 13y agoA competitor could also face charges for this sort of activity, couldn't they?
- aroch 13y agoLaw enforcement would have to work up the caring to actual track you down. There are hundreds/thousands/tons of [D]DoSs launched everyday from 10MB/s to colossal 400Gbps attacks. 99+% of attacks aren't going to be investigated.
- philwelch 13y agoThey have had some bad press lately....
- doyoulikeworms 13y agoCould this be in any way related to Julie Ann Horvath's treatment at the company?
- bleakcabal 13y agoI don't know, it's happened frequently in the past as well.
- testacular 13y agoSeems unlikely. I've used GitHub for a long time, and they've been unreliable for a long time. Fortunately git mostly works well, even when your repo has unpredictable reliability.
- lectrick 13y agoI didn't know the story. From http://thinkprogress.org/economy/2014/03/19/3416013/github-julie-ann-horvath-sexism/ http://thinkprogress.org/economy/2014/03/19/3416013/github-j... : "The sight of her male coworkers leering at a group of women in the office was the last straw for Github’s first female hire." Take a workplace with all-men, and due to sheer probability you're going to get a lot of leerers when any number of women walk in. That's really a bit unfair of an assessment. I'd like to see what happens when an attractive man walks into a workplace that is all-women.
- doyoulikeworms 13y agoI'm not commenting on the situation at all. Just speculating. I wouldn't have made that comment had I known that DDoSes on GitHub were not uncommon.
- mercurial 13y agoIt can be for a number of reasons, but I doubt script kiddies are champions of feminism. If it's professional criminals, they won't care one way or another.
- skylan_q 13y agoI'd like to see what happens when an attractive man walks into a workplace that is all-women I've been in this situation a few times and it makes me feel incredibly terrified.
- kjs3 13y ago
- bdcravens 13y agoMaybe there's a perception that since Github is mostly "free", there's less likelihood of prosecution? Maybe Github is most visible site that isn't heavily fortified against DDoS? Is there a common DDoS toolkit out there, and Github is in the example.conf?
- thiderman 13y agoIf you have a DDoS network, taking down something large like Github is a good way to display your power to any potential customer.
- bzbarsky 13y agoWhat makes you think other sites aren't being attacked as well?
- raindev 13y agoWondering who is continuously DDoSign GitHub last time...
- bleakcabal 13y agoOf all the sites I frequently visit/use, GitHub is by far the one to get DDoS the most often. Anyone has any insights on why?
- antonius 13y agoHard to specifically pinpoint, but clearly someone or a group of individuals that don't want to see GitHub succeed.
- talloaktrees 13y ago(black hat) hackers like to get people's attention, gain notoriety. Especially of their peers.
- trekky1700 13y agoI'm gonna guess people are just assholes. It's quite the target, considering the number of companies that rely on them for their day to day operations. They can do a lot of disruption/damage with it.
- Tobu 13y agoNormally I'd say extorsion, but I don't see why the attackers would keep it up for so long.
- lectrick 13y agoI'm not prone to violence but if I met someone who I was certain DDOS'd Github I'd certainly immediately punch them hard in the face. Github is a noble company with noble end-goals, and collaborative open-source is a revolutionary "work" idea. To see someone smash a bottle on the counter and threaten the nicest guy in the room gives me rage.
- wreegab 13y ago> I'd certainly immediately punch them hard in the face Looks to me you are prone to violence.
- baq 13y ago
- _cbb1 13y agoSeems like a waste of time for however is DDoSign.
- bdcravens 13y agoWaste of time? Not really. Think of all the projects that rely on it for package management, plugins, etc. Think of all the companies using private Github. Lots of lost productivity.
- Already__Taken 13y agoNot really, you won't deploy live code from github and if you are it's decentralised anyway so you just use your latest private clones and it's exactly the same. Everyone can keep working happily even using other syncing methods to collaborate. At worst it messes with the issue queues and integration services.
- _cbb1 13y ago+1, As stated, this isn't affecting the git repos themselves. :)
- billynomates1 13y agoMy company is in the process of moving from our own SVN server to using GitHub. Is this a bad idea in light of all these DDoS attacks recently?
- taspeotis 13y agoWell if you're only using GitHub for hosting the repo then you can still work with your copy of the repository while GitHub is offline (since you're in distributed not centralise version control territory). Git has a file protocol so you can also just sync your changes between one another via a network share of your repo. Or SSH or email each other pull requests.
- raindev 13y agoRight, just communicate directly with your colleagues when GitHub is down. This is exact workflow Git was designed to work with.
- jjdv 13y agoUpside > Downside. I'll take 15 minutes of DDOS outage / month over hosting my own stuff anytime.
- thiderman 13y agoGithub still holds quite a lot of nines in terms of uptime. It's just that it's extra visible when something big like Github goes down. The important part you should consider is to switch go git. I'd recommend starting to use Github, and if you find that it's down too much, look at alternatives or at hosting a solution yourself.
- vertex-four 13y agoNo they don't now. Because of the recent DDoSes, they're at 99.93%.
- jx2zhou 13y ago
- taspeotis 13y agoHonestly if I had the eleventy squillion bytes/s bandwidth of a large DDoS behind me and I wanted to DDoS GitHub ... I'd DDoS the status page too (just for shits and giggs). But on a serious note, is DDoS'ing a server that serves mostly static content way too hard? I imagine taking out one of GitHub's ways of communicating what's going on is appealing.
- randywaterhouse 13y agoThere are two types of DDoS attacks, which Github actually wrote about last week (thereabouts[1]), although you'll be unable to read the blog post until the site is back (unfortunately). But I can outline the two they discussed. The first is a "complex attack", which basically consists of doing things that make the server overload itself (repeatedly handshaking SSL, etc.), and that would be mitigated to some extent by reducing the complexity of the site (i.e. you can't SSL handshake with a server that only knows HTTP). Similarly, dynamic content could be an attack surface, so static content would make it more difficult to use such a complexity attack. The other type of attack, a simple bandwidth attack, doesn't care if your server is a top-of-the-line quad-chip Xeon server or an RPi in your basement, because all it does is exploit the bottleneck that is bandwidth. This attack just pumps packets like mad in your direction, and your network will likely become congested (and eventually fail) at some level other than your server (i.e. router level, firewall can't handle 100 Gb/s so the packets never even make it to your server). So, in light of the second there, DDoS'ing static content is just as easy as DDoS'ing dynamic content sites, as long as you're using a bandwidth type attack. I encourage you to read the blog post when the site is back up, it's definitely worth a read! [1] https://github.com/blog/1796-denial-of-service-attacks https://github.com/blog/1796-denial-of-service-attacks
- iclelland 13y agoIt seems back now, but in case anyone finds this comment the next time GitHub is under DDoS: http://webcache.googleusercontent.com/search?q=cache:KNnwGeDlspwJ:https://github.com/blog/1796-denial-of-service-attacks+&cd=1&hl=en&ct=clnk&gl=ca http://webcache.googleusercontent.com/search?q=cache:KNnwGeD...
- bttf 13y agoIf anything this is just a minor annoyance to users. If whoever is responsible gets a kick out of DDoS'ing a site like GitHub for no rhyme or reason they really should find better things to do with their time, i.e. they are losers.
- iancarroll 13y agoWhat happened to the Hubot command to redirect the attack to the contracted provider? Surely they can handle it.
- namuol 13y agoThis isn't as simple as it sounds; they'd need to identify DDoS traffic and reroute, while still allowing "legitimate" users through. But this may not be the sort of brute-force bandwidth DDoS that this was designed to handle either -- it could be a more targeted attack to existing bottlenecks in GitHub's architecture.
- iancarroll 13y agoThey made praising comments about the service last time.
- illuminated 13y agoThere are groups of people blackmailing companies for money, threatening with DDoS attacks if they do not comply. A client of mine, a European company gets these occasionally. The bigger the company/service, the bolder are the requirements. Crime, unfortunately, doesn't have feelings for such a great services as GitHub is. I hope GH will be able to mitigate the attack fast.
- teacup50 13y agoTo be fair to crime (... Heh), we're not doing ourselves any favors by putting all our eggs in one basket. How long until they graduate to exploiting GitHub and securing proprietary code from private source repositories, or forging commits to critical repositories (how often do you verify that every commit in the repo with your name on it is definitively yours?)
- illuminated 13y agoTrue, but these people usually want money - fast. The process you describe takes time and with time the risk of being caught expands. So I guess "real criminals" would opt for fast money rather than long term possibilities. The option you're describing seems more likely for various "agencies" and the likes...
- kjs3 13y agoSpot on. I have a number of clients who are EU gambling sites. They can count on an email or phone call about 10 minutes before the start of any and every big Football/Rugby/Cricket match to the effect "pay us X euros or we'll take your site off line". Since the betting activity is greatest right before the start, this could represent millions in lost revenue. These clients are very good at DDoS mitigation, but I also suspect they pay a lot of folks off as a cost of doing business. I also suspect that many of the attacks are set up by competitors, because it's pretty easy for a user to say "can't place my bet here, I'll go next door".
- bdcravens 13y agoSince most are on the github.io domain, maybe someone is fighting back against the propagation of 2048 clones?
- ahmedmhmd 13y agoCan this be a part of the story? http://thinkprogress.org/economy/2014/03/19/3416013/github-julie-ann-horvath-sexism/ http://thinkprogress.org/economy/2014/03/19/3416013/github-j...
- deleted 13y ago[deleted]
- joemaller1 13y ago...and let me help by trying to load the site. /dumbmonkey
- afhsfsfdsss88 13y agoThis is Chris Dodd and his new friends. http://www.webupd8.org/2014/03/how-to-install-popcorn-time-from-source.html http://www.webupd8.org/2014/03/how-to-install-popcorn-time-f...
- raindev 13y agoGitHub's website loads pretty fine for now. The team is working on the traffic filtering now, the status page said.
- thatinstant 13y agoLet's look on the bright side... At least 2048 is up! ;-) http://gabrielecirulli.github.io/2048/ http://gabrielecirulli.github.io/2048/
- iLoch 13y agoNo. No! Nononononononooooooooo
- ch4s3 13y agoIts back for me in Baltimore, MD
- raindev 13y agoMessage about DDoS attack could cause another wave of DDoS performed by thousands of users continuously refreshing a website to see if it's up.
- gtirloni 13y agoIn my teenage years I don't think anyone with access to a few servers hooked to T1 lines had to have any excuse to use that to DoS anyone. I always assumed they had some sense of fun (whatever that is) or were compensating for something else in their life. Anyway, I don't think we ugly bags of water have changed much in the last 20 or so years. I wouldn't read too much into this GitHub DDoS event.
- Arnor 13y agoThe pinnacle of asshattery... This is why we can't have nice things...
- bigtunacan 13y agoThese days when I see a GitHub post that they are experiencing a DDoS attack I have a slightly cynical reaction to it. I was at a software conference where we had thousands of people hitting GitHub to clone projects for workshops all that same time. They shut us down and said they were experiencing a DDoS... We were lucky that a couple of GitHub employees were at the conference and were able to contact the main office to get things straightened out.