TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

GitHub under ongoing DDoS attack

652 pointsby MosheZadaabout 10 years ago

56 comments

ggreerabout 10 years ago
The PRC&#x27;s DDoS of GitHub seems a little risky.[1] If GitHub is inventive (or desperate) enough, they could call on their users for aid. The perpetrators would immediately draw the ire of vast numbers of talented programmers. And GitHub is positioned to direct this ire toward useful ends. They could encourage users to contribute to GreatFire, or even start other initiatives and projects to stymie censorship. The outcome could easily be worse for the PRC than if the attack had never happened.<p>1. Even if this isn&#x27;t a PRC-ordered or sponsored attack, large parts of their infrastructure are being co-opted. If they aren&#x27;t criminally involved, they&#x27;re criminally irresponsible.
评论 #9284503 未加载
评论 #9284818 未加载
gogabout 10 years ago
As a paying customer of Github I want them to know they have my undivided support in staying strong against &quot;the bullies&quot;.
评论 #9284841 未加载
评论 #9284430 未加载
评论 #9285101 未加载
评论 #9288947 未加载
评论 #9286712 未加载
rsuelzerabout 10 years ago
From looking at the Javascript injection code (<a href="http:&#x2F;&#x2F;www.theregister.co.uk&#x2F;2015&#x2F;03&#x2F;27&#x2F;github_under_fire_from_weaponized_great_firewall&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.theregister.co.uk&#x2F;2015&#x2F;03&#x2F;27&#x2F;github_under_fire_fr...</a>) it seems like the quality of the script is pretty amateur.<p>They inject jQuery not once, but twice, and only use jQuery to make a simple XHR request. Perhaps they are worried about one instance of jQuery being taken down or made unavailable to them, but they really don&#x27;t need jQuery at all for something this simple.
评论 #9285874 未加载
评论 #9286117 未加载
评论 #9285553 未加载
评论 #9285833 未加载
golergkaabout 10 years ago
Can Github ask for US Government help with it, since it&#x27;s an attack by [presumably] foreign sovereign entity? It&#x27;s paying taxes in US, right — so it may expect some kind of protection, isn&#x27;t this what taxes are about?
评论 #9284712 未加载
评论 #9284898 未加载
评论 #9285801 未加载
评论 #9284915 未加载
评论 #9284859 未加载
maaaatsabout 10 years ago
&gt; <i>0:50 UTC - Into hour 71 defending the attack. Mitigation is holding and service is stable.</i><p>Wow, this has been going on for quite some time now!<p>&gt; <i>8:18 UTC - The ongoing DDoS attack has changed tactics.</i><p>Someone knows more about this new tactics?
评论 #9284476 未加载
rootlocusabout 10 years ago
The fact that someone would target GitHub for a massive DDoS attack makes me sick to the stomach.
评论 #9284444 未加载
jakhobabout 10 years ago
This attack is perhaps just a taste of something nastier. The GitHub infrastructure is rock solid and gives valuable real time information via its status dashboard . This seems ideal for measuring the impact of an attack before choosing a more critical target.
评论 #9284725 未加载
评论 #9284580 未加载
gbogabout 10 years ago
Hi, foreigner working in Chinese high tech company here. I wonder a bit, on which ground is this attack attributed to Chinese gov? It looks a bit unlikely to me. China has some cyber military but they are more likely to be pragmatic and choose wisely their targets. There&#x27;s a bunch of script kiddies but they would choose also something else. However it seems possible that many servers hosted in China are not secured and could be used for this attack, by some other people.<p>Just my first thought as an insider...
评论 #9284969 未加载
评论 #9285036 未加载
评论 #9285494 未加载
评论 #9285798 未加载
vixsomnisabout 10 years ago
Interestingly enough, if the attacks never stop (which is a possibility), the engineers at GitHub might still come up with a way to effectively nullify DDOS and continue their normal operations.<p>Which would be a massive advance in cyberdefense. It&#x27;s unlikely, but it would be a great example of &quot;natural selection&quot; (via their intelligent engineers&#x27; efforts) at work.<p>It will no doubt take ingenuity, but I don&#x27;t think any other website than GitHub is in the position to do this. Especially right now.
评论 #9285405 未加载
评论 #9286151 未加载
评论 #9285688 未加载
pfortunyabout 10 years ago
It would be interesting to compute the value (in MWh for example) of the energy used for this attack. Seems massive to me. Not just the traffic but the job performed by each computer.
kenrick95about 10 years ago
Blog post from GitHub related to this.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;blog&#x2F;1981-large-scale-ddos-attack-on-github-com" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;blog&#x2F;1981-large-scale-ddos-attack-on-gith...</a>
评论 #9284530 未加载
dengnanabout 10 years ago
Previous discussion <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9275041" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9275041</a>
ck2about 10 years ago
If this is China doing this, it makes me so upset the US has spent years and billions of dollars building up their economy instead of countries like Mexico.<p>Our relationship with them is almost as bad as our middle-eastern oil addiction.
评论 #9285949 未加载
SXXabout 10 years ago
This news about attack make me wonder why isn&#x27;t GitHub just blocked these repositories for all Chinese IPs. It&#x27;s would be logical after they censored certain repositories for Russian IPs:<p><a href="https:&#x2F;&#x2F;github.com&#x2F;github&#x2F;roskomnadzor" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;github&#x2F;roskomnadzor</a><p>Just in case anyone who try to access repos from Russia get something like that:<p><a href="http:&#x2F;&#x2F;imgur.com&#x2F;ytD5VYx" rel="nofollow">http:&#x2F;&#x2F;imgur.com&#x2F;ytD5VYx</a><p>And no I&#x27;m don&#x27;t support any of this and strictly against any censorship, but still it&#x27;s looks weird why GitHub agree to deal with Russians, but not Chinese.
评论 #9285354 未加载
butwhyabout 10 years ago
Out of curiosity, would Cloudflare be able to sustain the amount of inbound requests they&#x27;re handling?
评论 #9284569 未加载
评论 #9285549 未加载
评论 #9285506 未加载
binoyxjabout 10 years ago
Git well soon!
pstadlerabout 10 years ago
I&#x27;m looking forward for a post from GitHub describing what exactly was thrown at them and how they were able to mitigate it.
评论 #9284585 未加载
beefsackabout 10 years ago
As convenient as GitHub is, let this be a lesson to ensure you have multiple remotes for your repositories. The more popular GitHub gets, the more it will become a target from a wide range of vectors.
评论 #9284882 未加载
ionwakeabout 10 years ago
I&#x27;m confused - what is the reason behind it ?
评论 #9284374 未加载
评论 #9286087 未加载
gojomoabout 10 years ago
Can we be sure it&#x27;s not Chinese hacktivists seeking justice via a digital sit-in?
评论 #9284491 未加载
评论 #9285582 未加载
评论 #9284674 未加载
rellikabout 10 years ago
Thanks (China) for doing this on a weekend! Works out well for what I imagine are a large portion of Github&#x27;s paying users.<p>Please stop by tomorrow morning.
sillyryanabout 10 years ago
Anybody else like me who doesn&#x27;t understand why China is really doing this? Fun? The closest explanation I found is this - <a href="http:&#x2F;&#x2F;www.wsj.com&#x2F;article_email&#x2F;u-s-coding-website-github-hit-with-cyberattack-1427638940-lMyQjAxMTA1ODIzOTgyNDkzWj" rel="nofollow">http:&#x2F;&#x2F;www.wsj.com&#x2F;article_email&#x2F;u-s-coding-website-github-h...</a>
philjohnabout 10 years ago
Perhaps, if a country is shown to launch these kind of attacks[1], a second &quot;great firewall&quot; could be installed at peering points with that country, to filter out this kind of attack before it can reach the internet as a whole ...<p>[1] assuming, of course, this is the work of a government, and not simply some disenfranchised actors inside said government
评论 #9285056 未加载
评论 #9287149 未加载
fixxerabout 10 years ago
With as much ddos mitigation as github has to deal with, those developers&#x2F;admins have even brighter futures ahead of them.
sgloutnikovabout 10 years ago
This explains why I was unable to reach Github for a few minutes yesterday. But, I appreciate how they are handling everything.
andrewstuartabout 10 years ago
It seems governments are both protagonist and defenceless in cyber war.
评论 #9284411 未加载
josephmxabout 10 years ago
Most blog updates like this post the traffic they&#x27;re experiencing, is there a reason Github wouldn&#x27;t do that?
评论 #9284937 未加载
评论 #9284837 未加载
butwhyabout 10 years ago
So.. Every website running baidu analytics is going to show a warning popup to all visitors, on every page?
评论 #9284381 未加载
评论 #9284447 未加载
评论 #9284376 未加载
2DTFtxfDpNabout 10 years ago
Github could respond to requests that match the attack pattern with compression bombs: <a href="http:&#x2F;&#x2F;www.aerasec.de&#x2F;security&#x2F;advisories&#x2F;html-bomb&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.aerasec.de&#x2F;security&#x2F;advisories&#x2F;html-bomb&#x2F;</a>
ramigbabout 10 years ago
Each time i hear about DDoS attacks i wonder why we don&#x27;t have serious effective mitigation strategies even though there are brilliant computer scientists out there who always come up with very smart solutions, this is a genuine question and not a rhetorical one.
评论 #9285837 未加载
评论 #9285220 未加载
评论 #9285269 未加载
pkiabout 10 years ago
looks like github is announcing via prolexic for protection now?
评论 #9284433 未加载
whoisthemachineabout 10 years ago
If this is being funded and&#x2F;or perpetrated by a foreign government with China-like resources, I wonder how much extra capacity they have to expand the attack? Are they throwing everything they have at it now? I kind of doubt that.
mangelettiabout 10 years ago
If the attack crosses certain lines, it could be considered to be an act of war[1]. Considering many government agencies use GitHub[2], where are these lines drawn?<p>[1] <a href="http:&#x2F;&#x2F;www.forbes.com&#x2F;sites&#x2F;reuvencohen&#x2F;2012&#x2F;06&#x2F;05&#x2F;the-white-house-and-pentagon-deem-cyber-attacks-an-act-of-war&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.forbes.com&#x2F;sites&#x2F;reuvencohen&#x2F;2012&#x2F;06&#x2F;05&#x2F;the-white...</a><p>[2] <a href="https:&#x2F;&#x2F;government.github.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;government.github.com&#x2F;</a>
plicenseabout 10 years ago
What is Github&#x27;s backend like? Do they use cloud service providers or do they manage their own infrastructure?<p>Highly curious to know how Github is preventing the site from crashing down.
评论 #9284692 未加载
Tehnixabout 10 years ago
While many seem to immediately yell out that the PRC did it, conversely a hacker could just intend to make it seem like PRC was responsible by diverting the attention away from themselves and there to... I simply just don&#x27;t feel like PRC would be as stupid as to so openly DDoS a target, it doesn&#x27;t take much to be a bit more elaborate than that.
fideloperabout 10 years ago
I&#x27;d be interested to hear what this attack ends up costing GitHub in man power, bandwidth fees and so on. I wonder if any cost will be waived - I could see, for example, a large cost if they host DNS with AWS (although it sounds like they may host DNS at Akamai - I haven&#x27;t checked as I&#x27;m writing on the go).
kyledabout 10 years ago
Maybe not the best tactic, but they can selectively issue a 301, and point to a page that contains a new link to the project? The new page can be cached. In the future they can issue another 301 to point back to the original page. Hopefully web browsers will cache the new url.
giovannibajo1about 10 years ago
I wonder what happened if Google put Baidu Ad javascript into the Safe Browsing list...
评论 #9285516 未加载
eliyakabout 10 years ago
<a href="http:&#x2F;&#x2F;www.ijcat.com&#x2F;archives&#x2F;volume3&#x2F;issue7&#x2F;ijcatr03071006.pdf" rel="nofollow">http:&#x2F;&#x2F;www.ijcat.com&#x2F;archives&#x2F;volume3&#x2F;issue7&#x2F;ijcatr03071006....</a>
majkeabout 10 years ago
I must say I wonder a lot of the volume of generated traffic. Is that hundreds of connections? Thousands? Millions? What is the number of unique IP&#x27;s hitting them, bandwidth, etc.<p>Does anyone have any data on that?
Tistelabout 10 years ago
high level - how does one mitigate against a DDOS attack?
评论 #9284508 未加载
评论 #9284634 未加载
评论 #9284553 未加载
评论 #9284532 未加载
djhworldabout 10 years ago
This is having a knock on effect on HEROKU deployments with custom buildpacks, as I believe the deployer fetches the buildpack from github.
wiferaabout 10 years ago
How would these kinds off DDOS attacks affect a service that is behind a major CDN like cloudfront or cloudflare? Would this affect those?
paraditeabout 10 years ago
Why are there so many condescending comments about &quot;saving the Chinese people&quot;. Ask yourselves, are you really qualified to judge the Chinese people? Have you been to China? Have you been to different parts of China? What are the main sources that you obtain news? Are you reading the &quot;assumptions&quot; over and over again until they are &quot;assumed&quot; as facts? I liked this place when it used to be just about technologies.
评论 #9285536 未加载
评论 #9285652 未加载
GnarfGnarfabout 10 years ago
Does &quot;PRC&quot; refer to People&#x27;s Republic of China? Not clear.
评论 #9285284 未加载
codr4lifeabout 10 years ago
1) Fork everything you need. 2) Fuck up GitHub 3) Profit?
iamsalmanabout 10 years ago
This has been going on since early Friday for me.
muyuuabout 10 years ago
There are a few comments about China being involved. Is there any indication of that? I haven&#x27;t seen anything from Github themselves or elsewhere, just the comments here.
hatelove85911about 10 years ago
shit! no wonder why I&#x27;m constantly receiving error messages. why attack github? github is so great.
linzhabout 10 years ago
sorry for that. F<i></i>k GFW.
nickleeflyabout 10 years ago
Shame on GFW
WorldWideWayneabout 10 years ago
Why can&#x27;t GitHub just serve up pages with javascript that causes the user to re-attack the source of the initial attacks?
评论 #9285230 未加载
hackedipsabout 10 years ago
We will probably found out it was a mistake the the programmer has been &quot;fired&quot;.
评论 #9285273 未加载
hackedipsabout 10 years ago
The github service is nice, but do you really want to put your [code|website|etc] somewhere that can become inaccessible if some [person|group|criminal|government] decides they don&#x27;t like something about it?
评论 #9285426 未加载
评论 #9285442 未加载
评论 #9285378 未加载
verroqabout 10 years ago
Time to DDOS the entire Chinese IP space. Once the citizens experience network outages, they&#x27;ll be able to direct their anger at the PRC who started this bullshit.<p>PRC wins if Github null-routes the Chinese IP space, Github must stay up no matter what.
评论 #9284777 未加载
painabout 10 years ago
Gitchain needed please, if we can stop ignoring the root of the problem is the habit to preserve corporal central force.<p><a href="http:&#x2F;&#x2F;Gitchain.org" rel="nofollow">http:&#x2F;&#x2F;Gitchain.org</a> links with <a href="http:&#x2F;&#x2F;Factom.org" rel="nofollow">http:&#x2F;&#x2F;Factom.org</a> and needs complement not ignore the deep research and development environment we need to profoundly edit safed social structure.<p>(Their author failed to secure funding for Gitchain and then made Factom, while the issue needs equally relate each part as a side of research, expression, development log, proof, and safety machinations important to combine.)
评论 #9285958 未加载