19 ms·
GitHub under ongoing DDoS attack
- pki 12y agolooks like github is announcing via prolexic for protection now?
- butwhy 12y agoHow can you tell?
- devicenull 12y agohttp://bgp.he.net/AS36459#_peers http://bgp.he.net/AS36459#_peers
- dengnan 12y agoPrevious discussion https://news.ycombinator.com/item?id=9275041 https://news.ycombinator.com/item?id=9275041
- andrewstuart 12y agoIt seems governments are both protagonist and defenceless in cyber war.
- higherpurpose 12y agoNothing another surveill...I mean cyber law can't "fix".
- wongarsu 12y agoYeah, if we had a way for governments to legally and openly block arbitrary IP traffic we could prevent this. It's all necessary to fight against these commu... terrorists. It's totally necessary if we want to keep our freedom. /s
- csense 12y agoCommu-terrorists? It sounds like they're members of an Abelian terrorist group
- cocoablazing 12y agoThey've had 0 technology for a millennium, so more properly they would be a revolutionary integral domain.
- ionwake 12y agoI'm confused - what is the reason behind it ?
- oneeyedpigeon 12y agoGizmodo has some info. but I wanted to find a less trashy source; the register has a story [1]. In short, it's suspected that the Chinese government is behind the attack because there are some projects hosted on GitHub that it ideologically disagrees with. [1] http://www.theregister.co.uk/2015/03/27/github_under_fire_from_weaponized_great_firewall/ http://www.theregister.co.uk/2015/03/27/github_under_fire_fr...
- mrweasel 12y agoWhich raises the question: when will the rest of the world kick China of the internet? First it was redirecting Chinese internet users to random IPs, if the government didn't like their DNS queries and now they're doing ddos attack on a site that host a large percentage of open source code, used for a whole host of service and products. At some point it's going to make more economical sense to kick China of the internet.
- atmosx 12y ago> Which raises the question: when will the rest of the world kick China of the internet? Careful with that, because the moment some nation can kick out another nation out of the internet for whatever reason we're toasted. Plus, it's better to wait and see some hard evidence (if any can be found) before jumping into conclusions.
- est 12y ago> > Which raises the question: when will the rest of the world kick China of the internet? Well, that's exactly what the DDoS wanted, so the government could just happily control all access to Internet in mainland China The DDoS targets github.com/greatfire and github.com/cn-nytimes by their so called "collateral freedom" [1] Suppose github could just ban Chinese IP all together, but @greatfire could easily jump to another host and abuse ToS to hosting "neutral" political content, like bitbucket[2] Many webmasters have already banned all Chinese IPs, so gradually, every public hosting service will eventually ban all Chinese IPs, Chinese government could easily destroy the rest of circumvention methods [1]: https://en.greatfire.org/blog/2014/jan/collateral-freedom-faq https://en.greatfire.org/blog/2014/jan/collateral-freedom-fa... [2] https://bitbucket.org/greatfire https://bitbucket.org/greatfire
- iamsalman 12y agoThis has been going on since early Friday for me.
- butwhy 12y agoSo.. Every website running baidu analytics is going to show a warning popup to all visitors, on every page?
- blfr 12y agoTo some visitors. According to previous reports, only visitors from outside of China are sent the DDoS-ing version of analytics script.
- oneeyedpigeon 12y agoThat was an early issue, but - according to the GitHub status page - the attack has changed many times since that. Has anyone found any info. regarding what behaviour the attack is now exhibiting?
- dEnigma 12y agoWhat I would like to know is why they used a generic malware warning. Couldn't they send an alert with an actual explanation (in Chinese and English) of what's going on, so users are made aware of the issue?
- rootlocus 12y agoThe fact that someone would target GitHub for a massive DDoS attack makes me sick to the stomach.
- jacquesm 12y agoAny company that makes most or all of its money online is the subject of DDoS attacks for blackmail purposes, github a bit more so because the Chinese government doesn't like it. It's unfortunately a very normal thing these days.
- randomchars 12y agoWhat is the PRC's problem with Github?
- ricardobeat 12y agoThey host the 'GreatFire' org and other software to bypass their censorship firewall.
- spain 12y agoProbably because Github is hosting code they don't like (e.g. code used to bypass censorship).
- elvispt 12y agoIts due to these two repost most likely. https://github.com/greatfire/ https://github.com/greatfire/ https://github.com/cn-nytimes/ https://github.com/cn-nytimes/ Access to them is currently no possible though.
- mehhhhhhh 12y agoIt is: https://github.com/cn-nytimes https://github.com/cn-nytimes https://github.com/greatfire https://github.com/greatfire
- 12y ago
- maaaats 12y ago> 0:50 UTC - Into hour 71 defending the attack. Mitigation is holding and service is stable. Wow, this has been going on for quite some time now! > 8:18 UTC - The ongoing DDoS attack has changed tactics. Someone knows more about this new tactics?
- dujiulun2006 12y agoI saw this on Weibo earlier, NOT from a trusted source. But the first and third rounds have been confirmed. > 第一轮外域JavaScript,一个alert防住;第二轮外域img,Referer挡外面;第三轮GitHub Pages被D;第四波正在进行,是TCP SYN Flood攻击。 My translation: > The first round was cross-domain JavaScript, stopped with an "alert()". Second round was cross-domain <img>, stopped with referrer. Third was DDoS-ing GitHub Pages. Fourth is the ongoing TCP SYN Flood attack.
- sunflowerdeath 12y agoWhat about inserting invisible iframe to affected sites? I think it can not be prevented.
- dujiulun2006 12y agoSince GitHub (and other sites) can modify their webpages, something like: <script> if (window != top) top.location = 'http://www.google.com'; http://www.google.com'; </script> returned as a static webpage would do the trick.
- fotcorn 12y agoThis script can be disabled with the sandbox attribute on <iframe>: https://developer.mozilla.org/en-US/docs/Web/HTML/Element/iframe https://developer.mozilla.org/en-US/docs/Web/HTML/Element/if...
- dujiulun2006 12y agoIn that case maybe the other solution is better. Wow HTML5 is crazy...
- pfortuny 12y agoIt would be interesting to compute the value (in MWh for example) of the energy used for this attack. Seems massive to me. Not just the traffic but the job performed by each computer.
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- gog 12y agoAs a paying customer of Github I want them to know they have my undivided support in staying strong against "the bullies".
- butwhy 12y agoI was anticipating the second half of your sentence being something like "they better maintain 100% uptime or I'll be pissed off". Glad it wasn't.
- tomelders 12y agoI assumed it was implied.
- Swizec 12y agoAs a non-paying customer I have seen nothing but 100% uptime and perfect service. If it weren't for HN and Twitter I wouldn't even know Github was under attack.
- Vendan 12y agoSeriously, I had one page hang for about a second before responding, and honestly thought that was just my crappy wifi card(and may very well be).
- drdaeman 12y agoOAuth seem to have sporadic issues, which, I guess, may cause failures to "Log in with Github" auth on some occasions. At least I've seen a few "connection refused"/"timeout" error notifications from one of the sites I manage. Don't know the successful login counts, so no idea how high the error rate is.
- mckoss 12y ago"Bully" is rather too weak a label for the perpetrator. This attack is criminal. If carried out by a sovereign nation, perhaps an act of war. We don't allow foreign raiding parties to enter our country to loot private businesses. Neither should we treat this attack as a simple act of "bullying". GitHub should get the full support of federal law enforcement, if not the military.
- gojomo 12y agoCan we be sure it's not Chinese hacktivists seeking justice via a digital sit-in?
- chippy 12y agoI would imagine that they would have spoken up about it in that case.
- imron 12y agoI'd say it's far more likely to be hacktivists rather than the government.
- addicted44 12y agoWhy would Chinese hacktivists want to attack a project which increases their ability to get past the GFW?
- imron 12y agoHactivist by itself doesn't imply anti censorship. Just people who hack as a form of activism. In china there are hacktivists that are against the government and hacktivists that support the government's agenda and who hack for patriotic purposes and to avenge perceived slights against china. It's a well known phenomenon in china known as red hackers (or the Honker Union: http://en.wikipedia.org/wiki/Honker_Union http://en.wikipedia.org/wiki/Honker_Union ) And it's far more likely that they are behind this sort of thing. People with the skills to be a member of that sort of group have no need for either of the two relatively obscure projects hosted on GitHub to circumvent the GFW.
- sgloutnikov 12y agoThis explains why I was unable to reach Github for a few minutes yesterday. But, I appreciate how they are handling everything.
- binoyxj 12y agoGit well soon!
- ggreer 12y agoThe PRC's DDoS of GitHub seems a little risky.[1] If GitHub is inventive (or desperate) enough, they could call on their users for aid. The perpetrators would immediately draw the ire of vast numbers of talented programmers. And GitHub is positioned to direct this ire toward useful ends. They could encourage users to contribute to GreatFire, or even start other initiatives and projects to stymie censorship. The outcome could easily be worse for the PRC than if the attack had never happened. 1. Even if this isn't a PRC-ordered or sponsored attack, large parts of their infrastructure are being co-opted. If they aren't criminally involved, they're criminally irresponsible.
- joshuak 12y agoLooks to me like it's time for a DDoS X-Prize. 1. SSDP Flood 21% 2. SYN Flood 19% 3. UDP Flood 13% 4. UDP Fragment 12% 5. NTP Flood 8% 6. GET Flood 7% 7. CharGEN Attack 5% 8. DNS Flood 5% 9. ICMP Flood 2% 10. SNMP Flood 2% Eliminating these 10 attack vectors would account for 94% of DDoS attacks according to this visualization[1], as witnessed by Akamai over the last 30 days. Just the top 3 is more than 50%. Seems like a reasonable start on a way to measure success. Who'd like to sponsor? Or should I just spin up a GitHub repo for the code and a kickstarter for the prize money? [1] http://www.stateoftheinternet.com/trends-visualizations-security-real-time-global-ddos-attack-sources-types-and-targets.html http://www.stateoftheinternet.com/trends-visualizations-secu...
- mike_hearn 12y agoSYN Flood is already mitigated a long time ago with SYN cookies. The rest ..... well, it's basically just packets. I see this latest development as good news. The Javascript MITM trick was very clever because forcing github to render and serve a page is a lot more resource consuming than just firing packets at servers that ignore them (like a UDP or SYN flood). The latter can saturate network links until the sources are blocked, but those sources tend to be somewhat focused and don't shift much. An HTTP level attack driven by random web users means every request might have a different IP and it requires running way more of the app stack to be able to filter them out. If China is now resorted to SYN flooding then it means they ran out of better techniques.
- Tistel 12y agohigh level - how does one mitigate against a DDOS attack?
- brador 12y agoMake each "hit" cost as little to you in bandwidth/resources, and as much as possible to the attacker. National solution is to stop known bad nodes at the ISP level.
- jamescun 12y agoIn brief, you have more bandwidth than your attacker.
- nailer 12y agoEgress filtering in ISPs and backbone providers. People should not be able to syn flood in 2015.
- mdnormy 12y agoFor the basic attack, 1) Webserver - Set threshold and block offending IP [1] 2) TCP/DNS/SYNC/SSL/HTTP - Get DDoS-filtered IP and create GRE tunnel back to your server. You can get one for less than $10 from OVH, BuyVM or Ramnode. [1] http://deflate.medialayer.com http://deflate.medialayer.com
- kenrick95 12y agoBlog post from GitHub related to this. https://github.com/blog/1981-large-scale-ddos-attack-on-github-com https://github.com/blog/1981-large-scale-ddos-attack-on-gith...
- MetaCosm 12y agoI really wish they would post what the attacker wants removed so we could mirror it, post it, etc. The streisand effect is a good response to things like this I think.
- pstadler 12y agoIt appears that the first attack was targeted at https://github.com/cn-nytimes/ https://github.com/cn-nytimes/ and https://github.com/greatfire/ https://github.com/greatfire/ [1]. Accessing these two pages still responds with `alert("WARNING: malicious javascript detected on this domain")` which is supposed to be executed on the (innocent) client's browser. [1] https://news.ycombinator.com/item?id=9275381 https://news.ycombinator.com/item?id=9275381
- 13throwaway 12y agoYou can access those pages by removing the final slash.
- Narretz 12y agoI think among the sites is the GreatFire repo: https://github.com/greatfire https://github.com/greatfire
- butwhy 12y agoOut of curiosity, would Cloudflare be able to sustain the amount of inbound requests they're handling?
- lucb1e 12y agoHaven't seen many stats, but I'm pretty sure they could. If I remember correctly they deflected one of the largest we've ever seen which even made trouble for the Internet's infrastructure.
- _asummers 12y agoThis [1] is what you're referring to, I believe. [1] https://www.youtube.com/watch?v=w04ZAXftQ_Y https://www.youtube.com/watch?v=w04ZAXftQ_Y
- zaroth 12y agoL7 attacks come down to how much you can cache. If GitHhub was a purely static site, they wouldn't have trouble serving the requests themselves in any case. Github can solve this problem with CloudFlare to the same extent that Github's product can be replaced with a hundred nginx servers with 10Gbit uplinks, large RAM caches, and effectively zero CPU time spent on each request.
- majke 12y agoIs there any data on the size of the traffic? Anyway, even assuming the traffic is infinite, (to my understanding) most of the flooding IP's are from china. If that's the case it would most likely only affect the datacenter handling Chinese traffic. So even if it's really bad, only a (relatively small)[1] part of the world would notice. [1] relatively small in terms of the size of internet, not number of people
- deleted 12y ago[deleted]
- jakhob 12y agoThis attack is perhaps just a taste of something nastier. The GitHub infrastructure is rock solid and gives valuable real time information via its status dashboard . This seems ideal for measuring the impact of an attack before choosing a more critical target.
- deleted 12y ago[deleted]
- fixxer 12y agoAn interesting theory and I'm sure the attackers are savvy enough to collect data, but github is a pretty good target in its own rights.
- pstadler 12y agoI'm looking forward for a post from GitHub describing what exactly was thrown at them and how they were able to mitigate it.
- pstadler 12y agoFor what it's worth there's an article[1] from Craig Hockenberry. His servers were hit by massive amounts of traffic from China earlier this year, targeted (randomly?) at Iconfactory's website. The charts are quite impressive. [1] http://furbo.org/2015/01/22/fear-china/ http://furbo.org/2015/01/22/fear-china/
- johansch 12y agoThat (52 Mbit/s) was extremely small in comparison to modern DDoS attacks (which can be in the hundreds to thousands of Gbit/s). It could have been launched from a single raspberry pi with a 100 Mbit/s residential uplink.
- markvdb 12y agoAgreed about the extremely small attack, but one pi couldn't have done it. You'd need at least two or three. A pi will only get you to ~3Mb/s sustained ethernet. That's because ethernet is tacked onto the USB subsystem in a funny way.
- johansch 12y agoI guess I meant a raspberrypi 2. :) http://www.midwesternmac.com/blogs/jeff-geerling/getting-gigabit-networking http://www.midwesternmac.com/blogs/jeff-geerling/getting-gig...
- xorcist 12y agoThat doesn't look anything like the attack on GitHub. His server buckled from a couple of thousand requests because his webserver was misconfigured. GitHub probably handles an order of magnitude more requests on any normal day.
- plicense 12y agoWhat is Github's backend like? Do they use cloud service providers or do they manage their own infrastructure? Highly curious to know how Github is preventing the site from crashing down.
- yla92 12y agoIn an old post (in 2009)[1] from their blog, they host their stuff on Rackspace. [1] https://github.com/blog/530-how-we-made-github-fast https://github.com/blog/530-how-we-made-github-fast
- wifera 12y agoHow would these kinds off DDOS attacks affect a service that is behind a major CDN like cloudfront or cloudflare? Would this affect those?
- hackedips 12y agoWe will probably found out it was a mistake the the programmer has been "fired".
- hackedips 12y agoGuess you don't understand diplomacy.
- whoisthemachine 12y agoIf this is being funded and/or perpetrated by a foreign government with China-like resources, I wonder how much extra capacity they have to expand the attack? Are they throwing everything they have at it now? I kind of doubt that.
- deleted 12y ago[deleted]
- golergka 12y agoCan Github ask for US Government help with it, since it's an attack by [presumably] foreign sovereign entity? It's paying taxes in US, right — so it may expect some kind of protection, isn't this what taxes are about?
- fixxer 12y agoThat service only extends to the MPAA /s
- est 12y agoWell, the DDoS target, github.com/greatfire is funded by US government. So US government is fueling the DDoS in certain aspect.
- pjc50 12y ago""Cybercrime"" and ""cyberterrorism"" resources are only deployed (a) for securing more funding (b) for expanding US surveillance or sometimes (c) on behalf of big donors like the copyright industry. The US has no interest in saying "international cyberattack should be illegal" because then other countries might insist that it stop. They could go for a trade war escalation, but that would at some point have Apple as a casualty.
- diminoten 12y agoThat's not true at all, what the hell? Realize you're talking to folks who do this kind of stuff for a living, rather than just the random Internet denizens of most other websites. The FBI will regularly inform and assist companies who've been breached, for example. The US government is very interested in protecting US companies. That said, they don't quite have any guidance from congress on how to do that, so right now the assistance is limited. It is most certainly there, however, and your tinfoil-hat nonsense doesn't really fly.
- srj 12y agoWhen I was an admin of an IRC network we regularly reported large scale DDoS attacks to an FBI agent assigned to us. He didn't care. Some of those attacks took the network down for a while and resulted in many users moving to other networks. In at least two cases we even figured out the identity, address, and phone numbers of the people doing it and there was no movement on it. Then one day one of the people we had the identity of boasted on how he had briefly brought down the website of one of the democratic primary candidates. We forwarded that information and our case was reassigned to another agent and the person was arrested immediately. I absolutely think it's true that the US government is only interested in protecting established and powerful figures. I suspect the reason is career driven - defending the little guys isn't glamorous and probably has no promotion impact.
- fixxer 12y agoWith as much ddos mitigation as github has to deal with, those developers/admins have even brighter futures ahead of them.
- josephmx 12y agoMost blog updates like this post the traffic they're experiencing, is there a reason Github wouldn't do that?
- redsymbol 12y agoMaybe they've just too been busy to post it yet.
- josephmx 12y agoMaybe, but they have 272 employees, I'm sure most of those will be capable of a quick "we got this many requests in this many seconds". Though their team page doesn't list job titles.
- justinsb 12y agoI think the lack of traffic numbers speaks volumes.
- verroq 12y agoTime to DDOS the entire Chinese IP space. Once the citizens experience network outages, they'll be able to direct their anger at the PRC who started this bullshit. PRC wins if Github null-routes the Chinese IP space, Github must stay up no matter what.
- nick89 12y agoYes, just like "North Korea" hacked Sony's servers... Misinformation will happen on a large scale due to media outlets publishing the most enticing headlines. It will also push more anti-<insert country of choice> behaviour.
- verroq 12y agoHow much do they pay you to post here? The proof that it's China is irrefutable. Baidu's JS gets modified intercepted and modified. Target of the attack is the greatfire repository. I wonder who's behind this?
- nick89 12y ago> Time to DDOS the entire Chinese IP space. Once the citizens experience network outages, they'll be able to direct their anger at the PRC who started this bullshit. Sigh. I'm referring to Chinese citizens... Your post was wrong in every way, in stating that DDoS'ing Chinese citizens will make them angry with their government. Freedom of speech isn't as forward there (you know the whole GFW), so whatever the media pushes (I.e. what the government feeds them) will be what the vast majority of the public think... Even if you wanted to search for the "truth", the GFW could easily censor it like they already do.
- giovannibajo1 12y agoI wonder what happened if Google put Baidu Ad javascript into the Safe Browsing list...
- vpeters25 12y agoI think they should: traffic through the Great Firewall of China has been compromised, it's getting injected with malware and therefore cannot be trusted. Browsers and all safe browsing software should treat any traffic through the Great Firewall of China as malicious and show a scary warning in your browser asking to confirm before going there. The drop of traffic to Chinese servers and therefore customers would create such a big outcry it might make them stop.
- beefsack 12y agoAs convenient as GitHub is, let this be a lesson to ensure you have multiple remotes for your repositories. The more popular GitHub gets, the more it will become a target from a wide range of vectors.
- dorfsmay 12y agoAll your devs already have copies or your repos, and setting up a common server to share over ssh is easy (first thing we did on Friday). The bigger issues are dependencies, most people's builds these days depend on pulling dependencies from github.
- ck2 12y agoIf this is China doing this, it makes me so upset the US has spent years and billions of dollars building up their economy instead of countries like Mexico. Our relationship with them is almost as bad as our middle-eastern oil addiction.
- nacs 12y ago> US has spent years and billions of dollars building up their economy China is the one "funding" the US actually. From https://en.wikipedia.org/wiki/National_debt_of_the_United_States https://en.wikipedia.org/wiki/National_debt_of_the_United_St...: > $6.1 trillion or approximately 47% of the debt held by the public was owned by foreign investors, the largest of which were the People's Republic of China and Japan at about $1.3 trillion and $1.2 trillion respectively.
- nonissue420 12y agoClassic amateur hour over at GitHub. Another reminder that you may know how to hack, but you're no computer expert. It would be best to call for help than continue this charade GitHub. You failed.
- hmottestad 12y agoAre you saying that GitHub have failed? Could you explain why? Have you not been able to commit/push/pull/browser github because of the attack?
- gbog 12y agoHi, foreigner working in Chinese high tech company here. I wonder a bit, on which ground is this attack attributed to Chinese gov? It looks a bit unlikely to me. China has some cyber military but they are more likely to be pragmatic and choose wisely their targets. There's a bunch of script kiddies but they would choose also something else. However it seems possible that many servers hosted in China are not secured and could be used for this attack, by some other people. Just my first thought as an insider...
- polysics 12y agoThe MITM on HTTPS traffic that seems to be involved in the first attack stages is actually pretty good evidence.
- diminoten 12y agoThis might be part of the attribution: https://news.ycombinator.com/item?id=9275381 https://news.ycombinator.com/item?id=9275381
- gbog 12y agoThanks, so if I understand well, every js gotten from baidu cdn from outside China has a malicious code attacking github. Weird. It could be some test gone wrong, but I still don't buy Chinese gov attacking purposely and openly github like that. It's like showing your one time secret weapon way too early and on some wrong target. Or maybe it's a way to make some big noise to the left while the real target is discretely owned on the right.
- mangeletti 12y agoIf the attack crosses certain lines, it could be considered to be an act of war[1]. Considering many government agencies use GitHub[2], where are these lines drawn? [1] http://www.forbes.com/sites/reuvencohen/2012/06/05/the-white-house-and-pentagon-deem-cyber-attacks-an-act-of-war/ http://www.forbes.com/sites/reuvencohen/2012/06/05/the-white... [2] https://government.github.com/ https://government.github.com/
- philjohn 12y agoPerhaps, if a country is shown to launch these kind of attacks[1], a second "great firewall" could be installed at peering points with that country, to filter out this kind of attack before it can reach the internet as a whole ... [1] assuming, of course, this is the work of a government, and not simply some disenfranchised actors inside said government
- gibsonje 12y agoThat wouldn't work here, from what I understand. This attack is only using hosts outside of China, not within.
- davorak 12y agoThat could be made to work. The altered files are being served from ips within China even if the attack comes from those external to China downloading the altered files.
- WorldWideWayne 12y agoWhy can't GitHub just serve up pages with javascript that causes the user to re-attack the source of the initial attacks?
- fideloper 12y agoI'd be interested to hear what this attack ends up costing GitHub in man power, bandwidth fees and so on. I wonder if any cost will be waived - I could see, for example, a large cost if they host DNS with AWS (although it sounds like they may host DNS at Akamai - I haven't checked as I'm writing on the go).
- GnarfGnarf 12y agoDoes "PRC" refer to People's Republic of China? Not clear.
- qmalxp 12y agoYes.
- rsuelzer 12y agoFrom looking at the Javascript injection code (http://www.theregister.co.uk/2015/03/27/github_under_fire_from_weaponized_great_firewall/ http://www.theregister.co.uk/2015/03/27/github_under_fire_fr...) it seems like the quality of the script is pretty amateur. They inject jQuery not once, but twice, and only use jQuery to make a simple XHR request. Perhaps they are worried about one instance of jQuery being taken down or made unavailable to them, but they really don't need jQuery at all for something this simple.
- jayhuang 12y agothe jQuery is being injected from 2 different sources. The first being from a Baidu CDN, I suppose they anticipate some kind of attack on Baidu and included the 2nd one as fallback. As for jQuery being unnecessary for this job; agreed, but hey, it got the job done.
- aliakhtar 12y agoThey might be using jquery because it abstracts away the quirks of different browsers (I seem to remember that old versions of firefox and IE had different APIs for making XHR requests).
- TazeTSchnitzel 12y agoBut in this case there are no meaningful browser differences: var tag = document.createElement('script'); tag.src = 'https://github.com/greatfire/'; document.body.appendChild(tag); This works on any browser. Even IE6.
- ramigb 12y agoEach time i hear about DDoS attacks i wonder why we don't have serious effective mitigation strategies even though there are brilliant computer scientists out there who always come up with very smart solutions, this is a genuine question and not a rhetorical one.
- fdanconia 12y agoWell let's brain storm! How can one improve on what is currently out there? Faster recognition and diversion of traffic flow?
- riscy 12y agoI think the main difficulty is how to determine whether traffic is legitimate or not. Banning ranges of IP addresses is effectively denying service to non-attackers as well, so they win. The game is to soften their traffic's load on your system as much as possible while keeping things available.
- MichaelGG 12y agoMost of it comes down to shoving 10X traffic down a 1X pipe. You can write smart fast software, but if your wires are saturated... There is one common problem, and that is that the major transit carriers/ISPs allow you to spoof your source IP. That allows some attacks to be done easier than otherwise. But that's more of a special case and doesn't matter when there is hijacking going on like in this attack. Blocking attacks at the source is probably not a solution either, since you'd have to have a distributed way of getting filtering rules out to every ISP.
- fryguy 12y agoIf it were possible to stop some of that 10X before it even got to the pipe, would be the only kind of mitigation for that kind of attack. For something like that though, would require some pretty sophisticated firewall technology that lives outside of your infrastructure.
- pixl97 12y ago
- vixsomnis 12y agoInterestingly enough, if the attacks never stop (which is a possibility), the engineers at GitHub might still come up with a way to effectively nullify DDOS and continue their normal operations. Which would be a massive advance in cyberdefense. It's unlikely, but it would be a great example of "natural selection" (via their intelligent engineers' efforts) at work. It will no doubt take ingenuity, but I don't think any other website than GitHub is in the position to do this. Especially right now.
- mirashii 12y agoNullifying DDOS doesn't take ingenuity, it takes a big wallet, which Github no doubt has, but let's not pretend that its some engineering feat. If it was, a small company being ddosed would have a chance at fending it off all the same, but that's just simply not the case.
- vixsomnis 12y agoI'm not well-versed in the technical details of defending from DDOS, but unless it's a mathematical NP-complete problem, they have a chance.
- mirashii 12y agoHonestly, if you start by saying you're not well versed, how can you confidently make a statement about whether it is possible or not? Large scale DDOSes are usually the most damaging when they're high bandwidth (Layer 7 attacks can usually gradually be mitigated by well written firewall rules placed on the proximity of the network). When a DDOS is just maxing out the bandwidth coming into your network or sometimes even data center, no amount of clever algorithms can make your pipes bigger. For that, you need money. *edit fixed a minor typo
- vixsomnis 12y agoI'm not confident. I'm saying there could be a way to mitigate DDOS that we don't understand yet. It's unlikely, but possible.
- bzp1995 12y agoThe attack is an act supported by Chinese Government. it is an battle between a autarchic country and an company. China is good at it, a few days ago, Google issues Warning on Rogue Chinese Digital TLS Certs. The best response to the attack is to sell and not buy stocks of Chinese IT companies and not using any of their products. Here are some companies who work for GFW: venustech(启明星辰) Qihoo(NYSE: QIHU) 360.cn(360安全卫士) They don't care about how you feel but They DO and ONLY care about their money. China is military dictatorship. It is actually a Developed ISIS country. Here are some pics to help you understand China. https://pbs.twimg.com/media/CAe6HhaXIAAfyll.jpg https://pbs.twimg.com/media/CAe6HhaXIAAfyll.jpg https://pbs.twimg.com/media/B_phuEKU0AAoa0r.jpg https://pbs.twimg.com/media/B_phuEKU0AAoa0r.jpg https://pbs.twimg.com/media/B3clncbCAAALgED.jpg https://pbs.twimg.com/media/B3clncbCAAALgED.jpg
- hackedips 12y agoThe github service is nice, but do you really want to put your [code|website|etc] somewhere that can become inaccessible if some [person|group|criminal|government] decides they don't like something about it?
- hackedips 12y agoDownvoter, why did you down vote this? What I said is absolutely true. Sometimes the truth hurts.
- chrishas35 12y agoWhat service wouldn't be susceptible to such an attack? The only way to avoid it would be to not put your [code|website|etc] on the internet. That seems a bit extreme.
- hackedips 12y agoIt is not the DDos that I have a problem with. It is the centralization of the Internet that I have a problem with. Host your own shit, pay your own costs. This way if somebody gets pissed at you for your shit code, you don't cause problems for me and my shit code.
- kaeawc 12y agoYes. The nature of git means this has not stopped our workflow. Just because we can't update a central source doesn't mean we can't continue to get things done. Also, if a large enough entity doesn't like what you're doing, you're better off putting your code in Github/Bitbucket/etc because chances are you can't mitigate a DDoS of this scale by yourself.
- hackedips 12y agoIf you host your code on this "free" service and you cause a DDos because someone doesn't like what you are doing, are you going to pay for the mitigation costs to the free provider?
- SXX 12y agoThis news about attack make me wonder why isn't GitHub just blocked these repositories for all Chinese IPs. It's would be logical after they censored certain repositories for Russian IPs: https://github.com/github/roskomnadzor https://github.com/github/roskomnadzor Just in case anyone who try to access repos from Russia get something like that: http://imgur.com/ytD5VYx http://imgur.com/ytD5VYx And no I'm don't support any of this and strictly against any censorship, but still it's looks weird why GitHub agree to deal with Russians, but not Chinese.
- cmpb 12y agoIts because the requests aren't actually coming from China. China is redirecting worldwide users from Baidu to GitHub. Sorry, I don't have the link handy, but it was in that WSJ article on the front page.
- SXX 12y agoI do understand this, but if it's Chinese government behind attack the reason why they doing this it's these anti-censorship projects hosted on GitHub. Considering GitHub already supported censorship in Russia I see no reason why don't they just block access from China to projects that Chinese gov don't like.
- rst 12y agoBecause Github does not want to be complicit in Chinese government censorship, and if they blocked what that government obviously wants them to block, then they would be.
- sqren 12y ago> Because Github does not want to be complicit in Chinese government censorship I think you are missing the guy's point: what is the difference between Russian censorship and Chinese censorship? Github made a deal with Russia - why not also China?
- codr4life 12y ago1) Fork everything you need. 2) Fuck up GitHub 3) Profit?
- codr4life 12y ago1) Fork everything you need. 2) Fuck up GitHub 3) Profit?
- paradite 12y agoWhy are there so many condescending comments about "saving the Chinese people". Ask yourselves, are you really qualified to judge the Chinese people? Have you been to China? Have you been to different parts of China? What are the main sources that you obtain news? Are you reading the "assumptions" over and over again until they are "assumed" as facts? I liked this place when it used to be just about technologies.
- adventured 12y agoHN was never just about technology, for the same reason hackers don't only hack. That's part of what makes it so great.
- icebraining 12y agoWhich comments are you talking about?
- rellik 12y agoThanks (China) for doing this on a weekend! Works out well for what I imagine are a large portion of Github's paying users. Please stop by tomorrow morning.
- eliyak 12y agohttp://www.ijcat.com/archives/volume3/issue7/ijcatr03071006.pdf http://www.ijcat.com/archives/volume3/issue7/ijcatr03071006....
- majke 12y agoI must say I wonder a lot of the volume of generated traffic. Is that hundreds of connections? Thousands? Millions? What is the number of unique IP's hitting them, bandwidth, etc. Does anyone have any data on that?
- djhworld 12y agoThis is having a knock on effect on HEROKU deployments with custom buildpacks, as I believe the deployer fetches the buildpack from github.
- pain 12y agoGitchain needed please, if we can stop ignoring the root of the problem is the habit to preserve corporal central force. http://Gitchain.org http://Gitchain.org links with http://Factom.org http://Factom.org and needs complement not ignore the deep research and development environment we need to profoundly edit safed social structure. (Their author failed to secure funding for Gitchain and then made Factom, while the issue needs equally relate each part as a side of research, expression, development log, proof, and safety machinations important to combine.)
- Tehnix 12y agoWhile many seem to immediately yell out that the PRC did it, conversely a hacker could just intend to make it seem like PRC was responsible by diverting the attention away from themselves and there to... I simply just don't feel like PRC would be as stupid as to so openly DDoS a target, it doesn't take much to be a bit more elaborate than that.
- 2DTFtxfDpN 12y agoGithub could respond to requests that match the attack pattern with compression bombs: http://www.aerasec.de/security/advisories/html-bomb/ http://www.aerasec.de/security/advisories/html-bomb/
- nickleefly 12y agoShame on GFW
- muyuu 12y agoThere are a few comments about China being involved. Is there any indication of that? I haven't seen anything from Github themselves or elsewhere, just the comments here.
- kyled 12y agoMaybe not the best tactic, but they can selectively issue a 301, and point to a page that contains a new link to the project? The new page can be cached. In the future they can issue another 301 to point back to the original page. Hopefully web browsers will cache the new url.
- sillyryan 12y agoAnybody else like me who doesn't understand why China is really doing this? Fun? The closest explanation I found is this - http://www.wsj.com/article_email/u-s-coding-website-github-hit-with-cyberattack-1427638940-lMyQjAxMTA1ODIzOTgyNDkzWj http://www.wsj.com/article_email/u-s-coding-website-github-h...
- linzh 12y agosorry for that. Fk GFW.
- hatelove85911 12y agoshit! no wonder why I'm constantly receiving error messages. why attack github? github is so great.