15 ms·
China's Man-On-the-Side Attack on GitHub
- misiti3780 12y agoi read that github contains content that the Chinese do not like and that is why this is happening - what is the content they are so pissed about ?
- maxmcd 12y agoApparently the first attack was targeted at: https://github.com/cn-nytimes/ https://github.com/cn-nytimes/ and https://github.com/greatfire/ https://github.com/greatfire/ Source: https://news.ycombinator.com/item?id=9284547 https://news.ycombinator.com/item?id=9284547 Edit: They are also mentioned in the parent article (!!)
- jewbacca 12y agohttps://github.com/cn-nytimes/ https://github.com/cn-nytimes/ and https://github.com/greatfire/ https://github.com/greatfire/ host information about and software for circumventing the Chinese government's internet censorship systems -- which, among many other things, blocks access to, eg, Google, and The New York Times. Apparently they (the Chinese government) are not willing to entirely block Github traffic in the same way (presumably as an important tool for their software industry as well). This DDoS is an attempt to punish Github for not removing this block-circumventing information, and force the inaccessibility of those 2 repos specifically. It is being conducted in such a way that this is readily obvious but plausibly deniable.
- meric 12y agoAt the same time I think the censors do not have the political power to block github all together. "GitHub is the preferred tool for programmers to learn and connect with the rest of the world," he said in his Chinese-language post. He added that the site supported no political ideology, nor contained any reactionary content. "Blocking GitHub is unjustifiable, and will only derail the nation's programmers from the world, while bringing about a loss in competitiveness and insight." Lee's post was re-tweeted over 80,000 times on Sina Weibo, and featured in news articles on Wednesday. In another post, he later compared the blocking to trying to catch a mouse by burning the entire house down. http://www.computerworld.com/article/2493478/internet/github-unblocked-in-china-after-former-google-head-slams-its-censorship.html http://www.computerworld.com/article/2493478/internet/github...
- grandalf 12y ago> information about and software for circumventing the Chinese government's internet censorship systems -- which, among many other things, blocks access to, eg, Google, and The New York Times. The actual impact of the attack was to have thousands of news outlets and discussion forum sites mention and link to the github repos that offer circumvention. Further, by attacking Github, it's guaranteed that many of the most tech-savvy Chinese internet users will have the existance of the forbidden repos launched into their consciousness. Of course the Chinese government knows this and was likely not responsible for the attack. The attack would not be possible to commit by the actual perpetrator if there weren't such a knee-jerk bias against the Chinese government's internet censorship. Let it also be noted that the US Government censors lots of information too, both through so-called "official secrets" requiring security clearance granted by party members, and via laws that crack down on things deemed morally wrong, as well as illicit drugs.
- carboncopy 12y agoI'm not sure why you are being downvoted; I think differing opinions are the heart of HN. > so-called "official secrets" requiring security clearance granted by party members It appears that you're not from the U.S. or another Western-aligned country, security clearances aren't granted to or by the dominant political parties, but are an artifact of government and military/defense industry bureaucracy.
- tjradcliffe 12y ago> Of course the Chinese government knows this and was likely not responsible for the attack. This is an example of the logical fallacy of "argumentum ad stultum", or "appeal to stupidty". It goes like this: - X would be stupid. - No one would ever do anything stupid. : Therefore no one would ever do X. There are so many counter-examples to this argument that they hardly bear mentioning. People do stupid things every day of the week and twice on Sundays. Organizations multiply stupidity as often as they moderate it. It may be that this wasn't the Chinese government, but pointing out that it would be stupid for them to do so is not an argument against it at all.
- grandalf 12y ago
- deleted 12y ago[deleted]
- tn13 12y agoOur government is using our own money to spy and undermine our tech companies. What exactly is it doing to ensure American companies are defended ? Protecting us from international thugs like China's Communisty Party is the primary duty of our government.
- themartorana 12y ago"...should be the primary duty of our government." Fixed it? Although it's interesting to think about. Actual government retaliation would/could be seen as war provocation, especially if China holds on to any plausible deniability. Cyber warfare is currently very hard to prove, but even harder to hold accountable for. Even with DPRK, and our little shut-down-the-"internet" quiet retaliation thing that happened a few months back, North Korea still disavows responsibility. I imagine holding China actually responsible (in the way where it is recognized and acknowledged in the international community) is almost impossible... And thus we would be seen as the aggressors.
- rtpg 12y agoI don't think plausible deniability is really present here. Unlike other things where we "know" it was the gov't (if only because who else is going to spend the financial resources for the attack), here it's been pretty well disected that this is happening on the Great Firewall level.
- madez 12y agoA government doesn't have to react offensive against threats. It's also possible to provide defensive measures. In this specific case it could provide infrastructure, computing resources and personal to fend off the attack.
- Zancarius 12y agoActually, that would be interesting... Passing some sort of funding bill for the defense of US companies against DDoS attacks might be the only immediate option that could be done on a short time frame. Otherwise, it could (potentially) be something like the government holding on to spare capacity in some way/shape/form that it leases to affected companies for a very low rate. As we move on further into the 21st century, I can't see this as something that's going to go away. We definitely need to plan ahead.
- mraison 12y agoI still don't really get it. What's the actual goal behind the attack? When the Chinese government decides to block a website, I can at least understand their motivations, as bad as they may be. But DDOSing Github just seems to be pissing the whole world off for a few hours without any actual long term consequences.
- meritt 12y agoThey're probably demonstrating that the Chinese government can leverage nearly the entire Chinese internet userbase to DDOS anyone they want, at any time, and the easiest protection mechanism is to block Chinese IPs. Which is exactly want they want.
- girvo 12y ago> leverage nearly the entire Chinese internet userbase Well, not just Chinese users. Anyone who was accessing a site that used Baidu's analytics, regardless of where they came from. Things like this remind me why I like Piwik so much.
- igammarays 12y agoExcept this particular attack is not coming from Chinese IPs, rather from visitors of Chinese websites from outside China.
- rtpg 12y agoright, which is why unfortunately github couldn't counter by piping in some anti-china propaganda or something. As a sidenote though, VPN users are probably also affected.
- rst 12y agoMaybe they could -- it might not be a wise move, particularly given the political tensions which obviously exist already, and it would certainly be inflammatory, but it may well be technically possible. Github serves HTML over HTTPS, which means that if they started putting a few well-chosen words in Chinese in every HTML page served to China, the only thing the government could easily do about it would be to block github from Chinese users entirely -- which they've already tried once, and didn't keep up, presumably because cutting off github for more than a few days poses problems for their own domestic software sector.
- geetee 12y agoThis is some terrible JavaScript. And jQuery?
- eugeneionesco 12y agoBut it works, so...
- tiedmann 12y agoYeah, they ought to put it on GitHub and accept pull requests.
- interdrift 12y agoIt's obfuscated.
- baudtack 12y agoEven un-obfuscated it's pretty gross.
- vivaforever 12y agoThe USA made conspiracy theory, why would a government do such a boring thing?
- rwhitman 12y agoSo assuming that the Chinese government weaponized their firewall, the question is why are they using it in such a transparent way? Github is pretty firmly in the camp of open information, and used by nearly every web software engineer in the world. Surely they're not going to succeed at censoring these projects. As an attempt to project power and send some sort of warning, something about it just seems like a pretty flawed strategy.
- allochthon 12y ago> As an attempt to project power and send some sort of warning, something about it just seems like a pretty flawed strategy. I've been wondering about that myself. Perhaps the lesson to be taken away by most is that if you're not Github, you might not be able to effectively counter such an attack. That could lead to self-censorship.
- mwsherman 12y agoCan browsers or OSs not treat the corrupted Baidu analytics as malware?
- peteretep 12y agoYou'd think, wouldn't you. Or instead simply blacklist Baidu's analytics code completely. That will only hurt Chinese businesses using Baidu's product, and no-one else.
- TheDong 12y agoIt would also hurt american, or european, or any nationality of business that uses baidu to get more insight into chinese visitors. Baidu is certainly most popular within china, but not exclusive to them.
- teknologist 12y agoGoogle Analytics does all that, no worries
- kuschku 12y agoGoogle Analytics is, sometimes, blocked by the GFW – so, if you already sell out your users to Google, using Baidu wouldn’t be an unrealistic use case anymore.
- teknologist 12y agoExcept when it decides to ddos github
- deleted 12y ago[deleted]
- usrusr 12y agoI agree and I even think that this will be unavoidable, if that kind of abuse keeps going on. Government influence aside, Baidu would be free to host their analytics callbacks for the outside world outside of the GFW. If they stay accomplice to this kind of attack, no matter if forced or willingly, they will suffer.
- djent 12y agoDDOS seems to be impacting me intermittently here in Rhode Island https://imgur.com/pW59MG3 https://imgur.com/pW59MG3
- samlambert 12y agoHi Djent, Would you mind sending an email to support@github.com with details on what you were doing when that happened? Thanks
- huihe9849hjjgkg 12y agoWhen I went to github.com and then this page, this went away for me.
- dendory 12y agoIf the attack happens as described, and those two repos are aimed at Chinese people, why doesn't Github just block all requests to those pages that come from outside China?
- mkesper 12y agoThat would be suicide for fear of death.
- e79 12y agoI wonder how GitHub mitigated the attack so successfully. I can't find any baidu scripts using the injected code anymore (in fact the original tracking scripts on baidu's own domain return nothing), and GitHub is now serving the two repos that were originally targeted. What happened? Whatever it is, I'm glad they were able to mitigate the attacks.
- clippit 12y agoThe injection has been stopped and Baidu's script checks if there exists a referer.
- deleted 12y ago[deleted]
- zaroth 12y agoWhat do you mean "has been" stopped? There's no definitively stopping this without HTTPS, which I'm pretty sure hasn't magically "happened" in China in the last couple days. The GFW may have ceased its attack, but there's no check you can possibly add into an asset delivered over HTTP which can't be undone by the GFW. As long as there's a script being delivered over HTTP, the GFW can intercept that script request and replace with a script of its own.
- lgas 12y agoThere don't even have to be scripts being served -- as long as HTML is being served over HTTP they can inject their own scripts.
- clippit 12y agoI mean the Javascript hijacking has been stopped. This DDoS mixes several ways and during the js hijacking period, GitHub returns `alert()` on specific url for blocking browsers sending ajax requests. For now, the infected urls are back to normal.
- pmontra 12y agoThe attack is still going on. Details at https://status.github.com/messages https://status.github.com/messages They describe what they're doing to mitigate it. The latest message is 0:09 UTC Hour 118: Mitigation remains effective and service is stable.
- Rogerh91 12y agoGithub should have a huge call-to-action banner for every China-based web visitor that leads to this article translated into Mandarin. Xi Jinping Millionaire Relations Reveal Fortunes of Elite http://www.bloomberg.com/news/articles/2012-06-29/xi-jinping-millionaire-relations-reveal-fortunes-of-elite http://www.bloomberg.com/news/articles/2012-06-29/xi-jinping... Maybe add a Trollface gif while they're at it.
- stingraycharles 12y ago... which is probably blocked for every China-based web visitor anyway.
- Rogerh91 12y agoI should clarify: I don't think Github should link to the article directly (which is banned since Bloomberg has been banned ever since they published that article) A plain-text mandarin version in a repo somewhere would suffice to challenge the Chinese government's perception on what it really takes to censor the Internet. I honestly think it would just highlight how much they're losing against an organization of 300. Failing that, I'm going to resort to my default plan of finding the best way to donate money and time to help support Github, but I thought it was an idea worth entertaining.
- est 12y agoWell, that's a good analysis article and a good promotion for CapLoader. Wireshark indeed can do better on Gantt charts and graphs
- jjcc 12y agoMost people might not know what kind of organization GreatFire really is because too much context is missing. I only discovered recently it's not so simple. There have been a lot of talks about the behavior of GreatFire for quite for a while but most of the talks are in Chinese. There are some in English though, to give everybody a glimpse here is an example: https://github.com/greatfire/wiki/issues/1 https://github.com/greatfire/wiki/issues/1 I have an impression is GreatFire tried to weaponize all the users of github. They succeeded. I don't like the GFW either. But I think I'm very likely to be downvoted because the context of this incident is quite complicated. It's not easy to tell the truth especially when it's against most people's belief.
- chernevik 12y agoI'm sorry, what? Yes, it looks like Github has been pulled into a fight not entirely related to their initial mission. But that's how principle flows, you never know when the free flow of information will turn into a larger fight. I very much hope that they, and whatever networking partners they're working with, see this through. Because it's bullying bullshit by the Chinese government, trying to make people shut up because that government doesn't like what they are saying. GitHub is a company in America, not in China, and I hope they and their partners have the principles to stand up for the right to say what you think in America. If, by the magic of technology, those statements end up readable somewhere else, so much the better. Because if GitHub folds to this sort pressure, that pressure will just move on to the next site willing to host something that maybe the Chinese government doesn't like. You can make your accomodationist crap sound as reasonable as you like. It still amounts to giving in to censorship, and letting other people tell you what you can and can't say. I don't admire that, not one bit.
- carboncopy 12y agoI disagree that part of the mission of a for-profit organization includes responding to costly censorship measures from another country's government. Github would lose significant respect by folding, but unless they're ultimately fighting the U.S. Government's censorship, they don't have a claim in this fight. > that's how principle flows, you never know when the free flow of information will turn into a larger fight. Sure, whenever chernevik claims you need to enter a fight, you need to take it ;)
- pilgrim689 12y agoThis is a really well article outlining how the man-on-the-side attack on Baidu is carried out. The only flaw here is the logical leap that goes from "Baidu is being hijacked" to "Baidu is being hijacked by the Chinese government"
- wnoise 12y agoThe attack is not on Baidu, but via Baidu. Whoever is the attacker appears to control the great firewall of China. Who else would that be but the Chinese government?
- imron 12y agoThe Honker Union http://en.wikipedia.org/wiki/Honker_Union http://en.wikipedia.org/wiki/Honker_Union and/or the Red Hacker Alliance http://en.wikipedia.org/wiki/Red_Hacker_Alliance http://en.wikipedia.org/wiki/Red_Hacker_Alliance
- josefresco 12y agoThe line seems to be blurry - as I'm sure it is around the world when it comes to state level "hacking". http://en.wikipedia.org/wiki/Honker_Union#Relationship_with_Chinese_government http://en.wikipedia.org/wiki/Honker_Union#Relationship_with_...
- imron 12y agoSure, but the Chinese government has far more sophisticated ways of taking down sites so their own citizens can't access them, and they're not afraid to use them - even against big name sites. And in fact they often do, to help local companies providing the same offerings to prosper. The current DDoS attack just strikes me as too crude a method when they have so many other options available. If you were going to argue that it's just a retaliation towards GitHub for hosting these projects, then once again there are others sites the government is far more concerned about and they could use DDoS to bring them down with far less publicity than what the GitHub DDoS is generating. It just doesn't seem to make sense from either the method being used or the motivation behind the attacks.
- riscy 12y ago"Our analysis shows that only about 1% of the requests for the Baidu Analytics script are receiving the malicious javascript as response. So in 99% of the cases everything behaves just like normal." The way I see it, this has been a diagnostic test by the Chinese government, ensuring they have the power to globally take down any website (or servers) they please.
- allochthon 12y agoPossibly. But whoever's behind it end up looking kind of bad, since Github has not capitulated.
- coldcode 12y agoBut if it were 100% would github be able to survive?
- taternuts 12y agoDoes baidu have any say in this at all? Were they hacked to include this script or they just passively allowed it?
- rsuelzer 12y agoAs the article points out, the innocent request to baidu is being intercepted by China and replaced with a malicious script.
- JohnTHaller 12y agoThe Great Firewall of China can be used to "weaponize" any website passing through it. So, it can be used to inject a malicious script on Baidu delivered to non-Chinese IPs (as we see here) or Chinese IPs. It can also be used to inject a malicious script into Google AdSense for Chinese IPs as well as China has control of a digital certificate provider accepted by all major browsers and operating systems. One they have issued SSL certificates that can be used to impersonate Google et al this year. The bottom line is that, much like the matrix, everything within China is still part of that system and can be weaponized by the Chinese government. So, be sure you never have anything from within Chinese IP address space loaded by your web pages or apps.
- click170 12y agoAnd remember to remove the CNNIC Root CA from your certificate store unless you know you need it.
- fragmede 12y agoVarious sources are reporting that Baidu says they haven't been hacked, but I'm having trouble finding their source. eg, Ars - http://arstechnica.com/security/2015/03/github-battles-largest-ddos-in-sites-history-targeted-at-anti-censorship-tools/ http://arstechnica.com/security/2015/03/github-battles-large...
- corford 12y agoBaidu have not been hacked. Their servers reside inside the great firewall meaning any request from outside China has to traverse the GFW before arriving at Baidu's servers. During traversal of the GFW, the Chinese gov is modifying the Baidu server response with malicious javascript. Baidu has no say in the matter. They could try and help Github by swapping to only serving their analytics scripts over HTTPS. Even then, this would only help once a large majority of existing websites that use Baidu analytics have updated their website code to point to the HTTPS URL. Until then the attack would probably still continue to work.
- JohnTHaller 12y agoSince the question of "why" and "how" is coming up again, here's a quick summary I posted on reddit: From a few different analysis on HN and elsewhere... Baidu has an analytics product and an ads product, much like Google Analytics and Google AdSense, which are used on all kinds of websites via Javascript. China has set the Great Firewall of China to modify some of Baidu's assets so that any non-Chinese IP gets a modified version of the Baidu analytics and ad code. The modification causes every web browser visiting a Chinese site using a Baidu analytics/ad product to load files from the greatfire and cn-nytimes projects on github (both of which are designed to circumvent Chinese government censorship) once every 2 seconds. The effect is that people all over the world outside of China are unwilling participants in a DDoS against github. github has responded by taking both projects offline and replacing their content with a simple Javascript alert that shows a "WARNING: malicious javascript detected on this domain" messagebox. This causes the folks visiting baidu-infected sites to see the alert and know something is wrong with the website (hopefully not visiting it again). It also prevents the malicious Javascript from executing in a loop and reloading the site every 2 seconds. One takeaway is that you should always have a backup of your code and resources outside a single central site like github. Another is that you should never ever have any webpage configured to load any resources from a server hosted within China IP address space as it is vulnerable to this sort of attack by the Chinese government.
- facepalm 12y agoI think you got it wrong. The Baidu analytics code is not on the pages that are on GitHub. It is all over the place, and the Great Firewall occasionally swaps it out for the malicious script. There is no malicious code on the GitHub pages.
- UnoriginalGuy 12y agoYou must have misread because they never said anything like what you're claiming they said here.
- facepalm 12y agoThis is what they wrote: In short, this is how this Man-on-the-Side attack is carried out: An innocent user is browsing the internet from outside China. One website the user visits loads a javascript from a server in China, for example the Badiu Analytics script that often is used by web admins to track visitor statistics (much like Google Analytics). The web browser's request for the Baidu javascript is detected by the Chinese passive infrastructure as it enters China. A fake response is sent out from within China instead of the actual Baidu Analytics script. This fake response is a malicious javascript that tells the user's browser to continuously reload two specific pages on GitHub.com. Nowhere do they say that the script is only injected into the pages from GitHub.
- dav43 12y agoCould this be prevented by stricter CSP server-side?
- westiseast 12y agoFor me the most interesting thig about this incident is how the GFW is being used offensively. Most other governments so far have protested online censorship from a kind of moral standpoint, but not from a security standpoint per se. Now it's quite clear the GFW is being leveraged offensively - did anyone spot this capability previously?
- Laforet 12y agoIt only really ramped up this year. http://furbo.org/2015/01/22/fear-china/ http://furbo.org/2015/01/22/fear-china/
- westiseast 12y agoDon't know why your comment has been voted down, that's an interesting link and blog post and totally relevant to this thread :\
- hkon 12y agoDon't underestimate the chinese capability to down vote
- facepalm 12y agoIt seems the only solution might be to block all content from China? Great - now they have the firewall working both ways.
- Sir_Cmpwn 12y agoI had to do that for a website I ran a while ago. It's unfortunate but at the end of the day blocking China means that the rest of the world can continue to use your services legitimately.
- mike_hearn 12y agoIt's an identical setup to the NSA QUANTUM infrastructure, just in China instead of scattered around the western internet system. So I guess it's probably been used offensively in a more targeted approach for a while.
- rsuelzer 12y agoIf anyone from GitHub is reading this, I know that many of us would like to help. I imagine that the mitigation of this attack has been very costly. Is there a place we can donate to help offset the cost of this attack? Maybe I will purchase a subscription, but a one time payment would be preferable for many of us.
- toong 12y agoThe've raised $100M from a16z about two years ago [1] ? They should be fine without your donation. [1] https://news.ycombinator.com/item?id=4220353 https://news.ycombinator.com/item?id=4220353
- arasmussen 12y ago> China's Man-on-the-Side Attack on GitHub > and can conclude that China is using their active and passive network infrastructure China is a country that has 1.35B people in it. I guarantee you that 99.9% of those people had nothing to do with this attack. Can we stop using "China" and be more specific? It feels like it's blaming innocent people and possibly an entire innocent country. Chinese attackers? The Chinese government? People outside China who hacked Chinese internet infrastructure? At this point can we even be certain who specifically is to blame?
- EC1 12y agoNobody is sitting here equating the word "China" with the entirety of the Chinese people.
- deleted 12y ago[deleted]
- random_pr 12y agopeople know that it refers to the chinese government, rather than the people. you can be more specific if you'd like, but it is unnecessary.
- discardorama 12y ago> Can we stop using "China" and be more specific? Unfortunately, it is common usage to refer to the actions of a government as the actions of the country itself. You don't hear people say "The US Government invaded Iraq"; you instead hear "US invaded Iraq". You don't hear "The Kingdom of Saudi Arabia's government committed airstrikes in Yemen"; you hear "Saudis committed airstrikes in Yemen". To the broader point, about citizenry -versus- government: to some extent, as an American, I do feel a little responsible for my government's actions; and periodically do approach my senators and congresswoman to express my disagreement with the policies they have espoused. Maybe Chinese citizens can also chime in and ask their government (via Weibo or whatever medium is possible) why it's doing this to GitHub? Though probable most people on this planet would have no idea what "GitHub" is, so I'm not sure if anyone outside the tech world cares.
- bentcorner 12y agoCan I black-hole all of China in my hosts file? Off the top of my head I'm not going to miss anything, and I'd hate to be an unwitting participant in future attacks.
- jakeogh 12y agoUsing dnsmasq¹: $ echo 'address=/.baidu.com/127.0.0.1' >> /etc/dnsmasq.conf hosts file blocking is more difficult since you must list each subdomain. ¹everyone should
- Laforet 12y agoYou an certainly blackhole all baidu.con domains if you never use their services.
- peteretep 12y agoYou could use a tool like Ghostery to stop loading Baidu JS
- jacquesm 12y agohttp://www.ipdeny.com/ipblocks/data/countries/cn.zone http://www.ipdeny.com/ipblocks/data/countries/cn.zone
- songco 12y agoIn china, there's lots of similar thing, e.g. your android phone download a app from some site, the ISP(or others in your network path) can detect this(maybe by url) and return a modified version(e.g. add it's own ad or maybe complete a competitor's product of the original app).
- cxseven 12y agoNetresec should be able to gradually increase the TTL of their packets going to Baidu to see which hop or link is doing the hijack. They mention someone did this earlier with the iCloud hijack by using mtr and tcptraceroute, but it looks like these tools won't work as-is this time because the Github man-on-the-side attack waits for the HTTP GET request. It's probably stateless and if so could be triggered by a lone ACK with a proper HTTP GET inside. As long as they're not behind a stateful firewall, replaying their ACK at various TTLs to find the smallest TTL that triggers the hijack would probably do the trick. If the hijackers are clever they could make it look like the compromised hop is further away than it actually is, but not closer. Even so, this could be useful information and I'd love to see the result if anyone tries it. Edit: changed trace method so that it'd actually work.
- jackdawjack 12y agoI think this might be a daft question, but why can't they inject packets with a (roughly) appropriate TTL for the current sequence that they're hijacking? From the two examples shown one might think they're picking ttl's more randomly
- cxseven 12y agoThey could make the packets stand out less, but there'd still be the overlapping reply from the legitimate Baidu host, unless the attackers went full MITM. In case anyone is confused: we're now talking about the TTL of the packets coming from hijackers, whereas I was originally talking about the TTL of the packets going towards Baidu and the hijackers. The TTL the hijackers send won't affect the tracing method I was suggesting.
- dante9999 12y agohow is it possible that someone can carry this kind of attack without facing any kind of legal consequences? I know they are china we're not going to start a war with them but shit is there really no legal authority here?
- bsder 12y agoSo, the real question is how should we, the tech community, react?
- mike_hearn 12y agoMore SSL. This attack works because the firewall is capable of reading plain HTTP requests to spot the ones that are requesting the target javascripts, and then statelessly injecting raced packets. Neither technique works when SSL is in use. Even if China simply demanded the SSL keys from Baidu, they'd have to decrypt every single connection on the fly and significantly upgrade their infrastructure. I think the only way to continue this technique in the presence of widespread SSL use is to actually force Baidu to insert the malicious Javascript on their own servers.
- cbsmith 12y ago> Even if China simply demanded the SSL keys from Baidu, they'd have to decrypt every single connection on the fly and significantly upgrade their infrastructure. Umm... not really. All you'd have to do is select whatever subset of connections you want to inject code in to, and then terminate them with your own web server that has Baidu's SSL keys, then let the rest of the connections go through transparently to Baidu.
- mike_hearn 12y agoYou can't easily select that unless the stuff you want is on a dedicated relatively low traffic hostname. If everything is served off e.g. ads.baidu.cn then you have to decrypt all ad traffic, which is a lot.
- cbsmith 12y agoYou can select a random subset very easily at the layer-3/4 level. It's really not that different from just adding a host behind a layer-4 load balancer. ...and actually it doesn't have to be completely random. You could select specific IP addresses to intercept.
- datashovel 12y agoThis might not be a feasible reaction to the attacks, but in my mind the people who are "unsuspecting attackers" aren't necessarily trying to access GitHub in the first place. So, what if they set up automated rule to block all IPs (for a period of time) who show traffic patterns that indicate they are part of the attack, and then for all those IPs who are trying to reach GitHub purposefully but are currently blocked, give them explicit instructions on how to tunnel to regain access to GitHub while the attack continues. This way only those who are (a) part of the attack, and (b) want to access resources on GitHub need to do anything special. My guess is the number who would truly be affected by this are a tiny fraction of the total number of people who are part of the attack.
- Aissen 12y agoOne thing I don't understand: when you have the infrastructure to run the Great Firewall, why not simply generate the traffic yourself ? At this point you might just fake traffic from inside China with any kind of amplifiable no-state protocol. Sure, the TCP/HTTP attack might be a bit more resource intensive, but it should be doable with the same capabilities provided by their DPI infrastructure, no ? Edit: Last but not least, if we are sure that this attack is indeed coming from the GFW, then why Obama isn't calling Xi Jinping right now ?
- martinald 12y agoBecause non-chinese visitors (who aren't behind the Great Firewall) also get served this malicious javascript if they load up the code. It's not just Chinese visitors that visit these sites and therefore get the JS code.
- Aissen 12y agoOh, I had missed that ! I thought GFW was for clients, never thought it would apply on servers too.
- shawabawa3 12y ago> why not simply generate the traffic yourself ? Couldn't github simply null-route all chinese-origin traffic in that case? Currently the DDoS comes from everywhere except china
- Aissen 12y agoYeah, as I explained in reply to martinald, I had missed that. This is indeed a clever tactic. And very bad for Baidu's business, they must be outraged.
- adaml_623 12y agoThe point of this DDoS attack is to prevent people in China from accessing content on github. To null-route chinese-origin traffic would mean that the attackers win. (Obviously VPNs could be used to circumvent this null-route but they then become vulnerable to the same attack)
- deleted 12y ago[deleted]
- mingodad 12y agoCan the browser/os have an alert for such kind of behavior ? I mean if a script/program is sending repeated/too many requests stop/slow/show users a message ? Like when some javascript scripts is using too much cpu the browsers actually inform the user if he/she wants to stop then ?
- OneTwoFee 12y agoAre there any tools that would allow me to detect this kind of attack on my computer? I'd prefer not to DoS github.
- Hexcles 12y agoFYI, the referer (or referrer, whatever) method might not work well. The hijacked code does reside on only a few Baidu domains, but it is used (included by <script> tag) by TONS OF Chinese websites. The code is running in these numerous pages which use Baidu products, not just in Baidu pages. Thus, the referer actually varies a lot. It is really a cleverer solution to notice the subtle difference of the trailing slash.
- quarterto 12y agoI was under the impression that the attack had evolved since this tactic. Is there any word on what the current attack looks like? Or is it still this?
- jmngomes 12y ago"Based on reports we've received, we believe the intent of this attack is to convince us to remove a specific class of content." Does anyone know what that "specific class of content" is, or can shed some light over the motivation of the attacks?
- codesuela 12y ago> As can be seen in the code, the two targeted URLs are github.com/greatfire and github.com/cn-nytimes, which are mirror sites for GreatFire.org and the Chinese New York Times. GreatFire and NYT both use GitHub to circumvent the online censorship performed by the Great Firewall of China (GFW).
- jmngomes 12y agoI read that. Can someone shed some light over the motivation of the attacks?
- madez 12y agoDefending against an DoS-attack costs money. People try to spend as few money as possible. So, the theory is that the attacker wants github to take the repos down by making it costly to not do so.
- rufugee 12y agoIf Baidu served everything over https, would that effectively make this attack impossible unless the China GFW mitm'd the connections? I suppose that might add a significant server load to Baidu, but I wonder if we should just start accepting SSL as a cost of doing business on the internet. Of course, that would require Baidu's cooperation, and I suppose they might now want to raise the ire of the Chinese government. Also, I suppose the government could just use their own heavily trafficked sites to do this, but that should isolate it somewhat to Chinese IP ranges.
- MikeTV 12y agoSince the requests for hm.js are taking place over HTTP, even if Baidu started responding with 301's to reconnect over SSL wouldn't the GFW be able to just intercept the initial insecure request and respond with its own version of hm.js?
- akfanta 12y ago> that would require Baidu's cooperation Don't count on that. Baidu is part of the Chinese government gang. It is notorious for censoring/altering search results both for political and commercial reasons. I wouldn't be surprised if they were notified about this beforehand.
- rifung 12y agoI don't think they would be able to MITM the connections because your browser would detect that they don't own the certificate for the site. Unless of course, the CA is also compromised. I'm no expert so please do correct me if I'm wrong =]
- liugiul 12y agoSo, fuck that. The Chinese gov are bullies, but now they're treading on my lawn (or the lawn where I host my things, and all other things of interest/importance). What can I do? I already block ad tracking code in my browser with µblock. Can I send an email to some English-speaking representative of the communist party telling them to fuck off, and that I'll make sure to chose things not Made in China from now on?
- mariojv 12y agoGhostery blocks most analytics trackers: https://www.ghostery.com/en/ https://www.ghostery.com/en/ Google Analytics is blocked with that, I'd imagine Baidu Analytics would be blocked too. You can configure it to block / not block individual pieces.
- simple123 12y agoIf Great Firewall of China could modify the javascript, is it possible for U.S. to change it to a non-harmful script?
- simple123 12y agoPlease modify your hosts file, so you will not be a unwilling participants of GFW of China in the future! for example in windows: 127.0.0.1 libs.baidu.com 127.0.0.1 hm.baidu.com other chinese GFW attack host ....
- xenophonf 12y agoI wonder why TCP implementations don't monitor mid-stream changes to things like packet TTLs and optionally drop the connections as a result, or rather, I wonder what would break if they did something like that.