GitHub had connectivity problems
status.github.com
status.github.com
I guess I normally wouldn't notice, but there are currently some messages on there from today and yesterday and I found it hard to read as a story (either forwards or backwards) - I had to jump around a bit to figure it out.
Do we have any info on what steps github takes to prevent this? I ask as a paying customer (with both personal and corporate accounts).
It would be more likely to just have handful of high visibility repos.
That being said, I'm also curious about GitHub's efforts to prevent such a scenario.
Well, no. They would be inadvertently source-available. If the license doesn't comply with the Open Source Definition, it's not open source.
EDIT: Downvoted as usual for correcting false impressions about how free software and open source works.
Are you seriously suggesting that the OP you responded to was comparing "stolen" or "leaked" software to open source? That is probably why you're being downvoted, not because people around here have a false impression as to what constitutes open-source.
Moreover, it reflects a critical flaw in the open source dogma as compared to free software. Open source puts source code at the forefront, which is fallacious. The key elements are the ability to run unfettered, study, modify and redistribute identical or modified versions. The source code is a necessary precondition for properly exercising those freedoms, but not a central focus in any real sense. It is easy to misinterpret "open source" as being about publicly viewable source code, and many companies have exploited this to their advantage presently or in the past (GitHub with Atom, Epic Games with UE4, etc.)
The OP was explicitly calling such stolen or leaked software open source. Please read more closely.
"We use better than industry standard encryption on private repo data, encrypted with AES-1024 and encrypted in transit via TLS-3 etc etc..."
But, I don't know. What was that quote? "Don't put anything on the internet that you wouldn't want to see on your grandma's coffee table."
Also, if GitHub is down you can still fetch your dependencies from somewhere else.
I once worked in a group that used SVN for SCM, mediawiki for wiki and Trac for tickets. I voiced my opinion about that setup many times but management felt that was the most efficient way to work...
Products like indefero/srchub have all of that from a single interface and it's very easy to maintain. I don't know how easy gitlab is to install/maintain - perhaps sytse can pop in and go into detail about that. Assuming the system works the maintenance would be minimal.
And then you can set a daily nightly cron for: sudo apt-get update sudo apt-get install gitlab-ce
Don't forget to take snapshots of your server for backups.
AHHHH!!!! Don't recommend doing that. Only those who are crazy do that. Imagine waking up in the morning and your SCM system is broken due to an update that was automatically applied - I wouldn't want a sysadmin (or developer) to see that before their first cup of coffee.
When you update - does it automatically apply migrations or other database upgrades that might be necessary?
By default the Omnibus packages will stop, run migrations, and start again, no matter how “big” or “small” the upgrade is. The behaviour can be changed by adding a /etc/gitlab/skip-auto-migrations file.
Obviously if you installation grows you can review the needed upgrades in advance and prevent downtime in most cases.
Another thought occurs to me though, I guess one of the problems when writing a DDoS is measuring how well it performs. The GitHub status screen provides a lot of useful metrics for tuning such an attack.
1. Github is very well known and cater specifically for the tech crowd. So, an attack on Github is more likely to be talked in the tech crowd, which I would assume the people who would try out DDoS attacks be more likely to be part of. Validation is a weird thing.
2. In a convoluted sense, taking down Github doesn't harm as many bystanders. If that makes any sense...
3. As you've mentioned, very clear useful metrics for the attacks.
4. Crowding effect? Maybe attacking Github has become some 'cool' things to try in that community. I'm just imagining at this point.
And bragging rights. Imagine the street cred you get amongst that community if you take down something like github...
It could be related to things like this: https://news.ycombinator.com/item?id=10101469
https://github.com/blog/1981-large-scale-ddos-attack-on-gith...
http://arstechnica.com/security/2015/04/ddos-attacks-that-cr...
I know, we should keep building up their economy by manufacturing nearly everything there, that should stop them.
[1]: https://wikileaks.org/Transcript-Meeting-Assange-Schmidt#996
I look forward to the day governments start to fund free software, for example through the GNU project. Then we'll all have better tools.
Actually, there were already some fundings. Germany funded GnuPG to port it to Windows.
What do I care what is the new world record in sprinting? But I very much do care about a new release of libreboot, libreCMC/openWRT or Debian!
I hope one day we will see peaceful international competitions between nations of who can provide the best/most used free software.
BTW, it is hear, hear ;).
That's because it's not. Governments are not reliably good, and their money comes with far more strings than private money.
The FSF have it right: people should write free software because proprietary software is immoral.
Have you ever worked on a government-funded project? The Tor folks have and do. :)
> ...[P]eople should write free software because proprietary software is immoral.
USGov does fund Libre and Open Source software. One big example is the Tor Project.
edit: a more recent (?) link https://github.com/cjb/gittorrent
Or, we could both set up HTTP servers on our respective machines and simply push to each others repos.
PRs, wikis, issues are the reasons why we use github...
An org-mode file named 'issues,' with each issue under its own heading?
A directory named 'issues,' with an org-mode or CommonMark file for each issue?
A directory named 'issues,' with a directory for each issue, with CommonMark, org-mode or restructured text files for each person's comments?
http://ditz.rubyforge.org/ http://pitz.tplus1.com/ https://github.com/jeffWelling/ticgit http://www.bugseverywhere.org/
... and probably others. That's just based on a quick Google search.
One nice thing about this approach is that your issue's state follows your code through merges. When you fix the bug you mark it as 'fixed' and commit that change to a branch. When it gets merged into master, the 'fixed' status gets merged as well.
(PS: why cannot I reply to paulrouget's message?)
Back to work everyone, git is distributed version control so we don't need pull requests or gists or any kind of easy-to-read historical record that is also accessible for non-engineers.
That might not be your specific problem, but I'm guessing a few people have this problem today. I'm glad I check my libraries into my local repository :) Using a local fall-back for popular libraries hosted on cdns is a good idea too.
To be fair, I don't do it because I think it's stupid not to, I do it because I often work on my laptop while travelling and have to be able to continue to work without an internet connection :)
https://pulse.turbobytes.com/results/55dc40faecbe400bf800146... traceroute looks ok..
But I don't think anyone can say for sure.
Current: http://github.com/jsjohnst/project
One (of many) better approaches: http://jsjohnst.github.com/project
If you really want the Chinese people to protest, try cutting them of from the Internet for a few weeks. Let's see if that won't work.
They also probably feel emasculated that South Korea told their pet regime to knock off the stupidity and China and North Korea capitulated to their demands yet again. The timing of this is far from a coincidence. China's foreign policy is almost 100% hinged on having North Korea attack the west with impunity and they don't like that Park is actually pushing back against this dynamic. So now China is having its hissy fit on Github instead on the Korean peninsula.
Yeah, lets keep rewarding them with factory contracts, right guys?
Also if you're going to respond include a reason why you disagree
There is also little benefit in it. If the subdomains only point to the same servers then the same level of traffic will still take them all down, but if different subdomains point to different servers then it makes attacks easier because the attacker only needs enough resources to overwhelm 5% of the servers instead of all of them.
edit: TIL my English wasn't as good as I thought.
> In British English it’s absolutely fine to treat most collective nouns as either singular or plural – you can say my husband’s family is very religious or my husband’s family are very religious.
http://itre.cis.upenn.edu/~myl/languagelog/archives/001874.h...
etc.
With something like collective nouns it's probably wrong to make blanket statements about correct and incorrect, even if you're a prescriptivist not descriptivist.
EDIT: And while I love (but am hopeless with) English usage this is the least interesting bit of the submitted article.
Note while 'just' a style guide, The Economist - like me - seems (note not 'seem' ;)) not to consider "Tesco" _et al_ to be collective nouns _per se_.
> A government, a party, a company (whether Tesco or Marks
> and Spencer) and a partnership (Skidmore, Owings &
> Merrill) are all **it** and take a singular verb.Examples: GitHub IS a web site. GitHub is a SAAS app.
The only plural aspect to GitHub is its employees and they are not being DDoSed. The web site (singular) is.
I'm not going to bother explaining the problems with "under DDoS" or the other issues with this sentence.
The "website" (or "app") is the abstract thing that runs on those servers. The servers are trying to service a flood of incoming tcp connections and http requests from rogue clients, which slows them down.
So "are" is not entirely out of place, but of course we all got the message ;).