7 ms·
GitHub hit by DDoS attack second day in a row
- ihuman 14y agoWho would try to disable github?
- tegansnyder 14y agoThank is exactly what I was thinking. Who in their right mind would want to do that?
- maratd 14y agoSomeone who wants to test the limits of their botnet and technique. Can you think of a more tech savvy target?
- lucisferre 14y agoAmazon.
- bkanber 14y agoAmazon has a service outage every time you look at it funny, much less a DDoS... hyuk, hyuk
- donavanm 14y agoDDOSs are typically defeated through buying lots and lots of transit. That's an exercise in outspending your adversary. A small entity like github should be trivial to saturate.
- adgar2 14y agoGoogle. Amazon. Microsoft. Apple. Facebook. Most startups.
- tensor 14y agoMost startups? Name even one startup in the same league as the others you've named.
- SethMurphy 14y agoAttacking a rails application, you would be proud of that? Rails sites are not exactly known for their performance.
- Tipzntrix 14y agoI know a few governments who would be more than happy for github to be disabled.
- JoeCortopassi 14y agoCare to elaborate why GitHub would be a target for a state sponsored DDOS attack? Seems a little far-fetched, for a website that is virtually unknown outside of the developer community
- rcthompson 14y agoIn the broadest sense, github is a site where anyone can upload and publicize any file of reasonable size. Depending on who is uploading what, that could easily make them a target.
- moe 14y agoIn the broadest sense, about 10 million web-forums and similar sites also match your description... Why would they go for github of all things?
- Tipzntrix 14y agoWhile not as famous as Tor in Iran, for example, there are VPN implementations on GitHub, in addition to what rcthompson said.
- Dirlewanger 14y agoThere's some statistic out there somewhere from some paper which found out that like 3 out of every 4 (or something ridiculous like that) cyber attack on the US government comes from China so...it's not that farfetched.
- dbaupp 14y agoI don't quite see how that is relevant to a non-US government entity like GitHub.
- boomzilla 14y agoIt could just be some rogue deployment script running from EC2 that are a little more active that it should be. Imagine someone is deploying their 1GB repo from GitHub to 100 small EC2 instances :)
- Cherian 14y agoMy startup cucumbertown.com is hit with similar issues. Initially we blocked all Ec2[1] & spamhaus ip list. But then realized Flipboard proxies[2], some blog aggregation proxies etc are based on Ec2 machines. What would be a good way to block such rogue machines? Is there a community sponsored list or Ec2/Rackspace ips that are creating issues? https://forums.aws.amazon.com/ann.jspa?annID=1528 https://forums.aws.amazon.com/ann.jspa?annID=1528 http://flipboard.com/browserproxy/ http://flipboard.com/browserproxy/
- Caballera 14y agoBanks were being hit the first week of October, then I know some VoIP servers were being hit such as Callcentric by DDoS. I can see why the banks were hit, but not why so many much smaller businesses are being attacked.
- RileyJames 14y agoI would think being small(er) and having 100M in the bank makes github a pretty good target, unfortunately.
- i386 14y agoI don't think so. If you we're hosting GitHub you would figure out pretty easily if it was related to cloning a specific repo from AWS and just disable the account hosting the repo.
- rorrr 14y agoIt's the standard weapon of botnet blackmail. Target a large site, bring it down, ask for money. Fighting DDoS attacks is not trivial, especially if you're against a sophisticated botnet, and your code has multiple slow parts.
- chrixian 14y agoit was sourceforge
- tonfa 14y agoBack in 2009 when it happened to bitbucket, this was afaik due to hosting a particular project (hurting bitbucket was a side effect of hurting this particular project, some communities seems to be happy to resolve issues with DDoS attacks...).
- redsymbol 14y agoMaybe it's because I just personally identify with the founders of github (i.e. entrepreneurial sw engineers), but I'm starting to get mad at whoever keeps doing this. Here's hoping that with all the smart people this is affecting, the people responsible will be tracked down and exposed.
- carlosaguayo 14y agomay whoever is doing this be doomed to use SVN the rest of their lives ...
- sergiotapia 14y agoYou ice baby! Ice cold!
- emeraldd 14y agoForget svn ... May they be doomed to use RCS for the rest of their days ...
- feisuzhu 14y agoForget about version control, may them be using pen drives to copy code around for the rest of their days...
- richadams 14y agoSVN's too good for 'em.. let them use Visual Source Safe forever.
- onyxraven 14y agoAnyone else having trouble connecting to GitHub via SSH from AWS?
- kmfrk 14y agoJust SSH in general. I can't push to my repo from my laptop in most cases.
- jsanroman 14y agoMaybe I'm naive, but could they be stealing someone's code? Otherwise I think it's just someone who's trying to prove something.
- arcatek 14y agoYou can't steal anything by DDoSing. You could only kill the servers until the next reboot ... and all over again. No data will be compromised, but it will still be a pain in the .. head.
- codinghorror 14y agoCan we please use some of that 100 million investment to buy an infrastructure that is more resilient to these kinds of DDoS attacks? Pretty please? This is a service I pay for and my business relies on. Having it down three times in three days impacts our work.
- Caballera 14y agoI'm sure that's what they are doing now. However it takes time to setup new servers as well as writing code (that's been throughly audited) to help protect their existing and future servers.
- bkanber 14y agoDid it really impact your work, other than slightly inconveniencing you? "UGH GitHub down again, I guess I have to go work on something equally as important for upwards of an hour" I call shenanigans on you, good sir.
- codinghorror 14y agoSince when is it OK for the services I rely on and pay for to even slightly inconvenience me ... for three days in a row? Since never. At least for businesses that want to remain an ongoing concern.
- bkanber 14y agoDevil's avocado here: let's say you pay $100/mo for a gym membership and they shut down three days in a row because somebody called in a threat. How upset would you be at the gym? A malicious attack by a third party is different from, say, the gym allowing black mold to grow in the locker room. I'd quit a gym if they had black mold. That's mismanagement. I wouldn't quit a gym if malicious third party intervention inconvenienced me. Besides, GitHub is obviously more concerned about this than you or I could ever be. And having money doesn't make infrastructure magically appear. I pay GitHub too. My company relies on it. I, too, was slightly inconvenienced this week. I was also slightly inconvenienced when I had to make a u-turn because the Battery Tunnel southbound on-ramp was closed. So what? In summary: shenanigans! Good day sir!
- w1ntermute 14y agoIt's pretty crazy how just a couple thousand LOICs can incapacitate a site as prominent as GitHub. I wonder how many machines are involved this time.
- dsl 14y agoLOIC is pretty easy to filter, it's about a 1 out of 10 on the difficulty scale. Either GitHub as a whole is technically incompetent, or they are getting hit with something built by big kids.
- peripetylabs 14y agoPerhaps I'm misunderstanding: I thought one goal of DVCS was to remove central points of failure? In that sense, isn't a central "hub" regressive? I wonder if there's a way to host Git repositories with static files, say, on Amazon S3... That would be neat.
- zalambar 14y agoGit is distributed and there's no reason you should have to stop working, or committing, just because github is temporarily unavailable. At least for dependencies only on git. Losing access to wikis, pull requests, and issues may be a problem for some teams. http://ozmm.org/posts/when_github_goes_down.html http://ozmm.org/posts/when_github_goes_down.html has a good summary of quick ways to keep using git without github.
- bitcartel 14y agoFossil has built-in issues and wiki. It just never became popular.
- threedaymonk 14y agoThe only prominent Fossil user I'm aware of is Zed Shaw, and he's since recanted after losing data and having trouble upgrading: http://sheddingbikes.com/posts/1306005291.html http://sheddingbikes.com/posts/1306005291.html
- zrail 14y agojgit, the version that Eclipse uses, has native S3 support. I run my own local git server that transparently backs up every push to S3 this way. http://blog.spearce.org/2008/07/using-jgit-to-publish-on-amazon-s3.html?m=1 http://blog.spearce.org/2008/07/using-jgit-to-publish-on-ama...
- mattdeboard 14y ago>Perhaps I'm misunderstanding: I thought one goal of DVCS was to remove central points of failure? In that sense, isn't a central "hub" regressive? This meme is getting really, really tiresome. Github being down is NOT a central point of failure. Most people know that setting up your own git server is trivial, literally a 3-4 step process. We know that we don't lose our files, our history, our working tree, etc. The "git" in Github is easily replaced. The "hub" part has its own value. The communication tools, the well-presented diffs, the inline-editing capability, issues, wiki, etc. That's the value people are gnashing their teeth over.
- didip 14y agoI can't wait to read their post-mortem. Must be pretty exciting.