Github.com unavailable due to a large DDoS attack
status.github.com
status.github.com
Also, I'd be interested to know how complete lack of service is 'mitigating a DDOS attack' - to me it sounds like 'successful DDOS attack'.
It also depends on the ingenuity of the DDoS attack, none of which are known to the public so you can't really say anything sensible about it.
If the anti-DDoS mitigating tools they are using aren't working nor is using other services like Prolexic that's usually hint enough that this isn't particularly common or easily filtered out.
You can gripe on all the companies and tools if you will but a good DDoS is quite a bit more complex than 'just filter away the bad crap'.
See #4 of the 12 timeless networking truths:
(4) Some things in life can never be fully appreciated nor
understood unless experienced firsthand. Some things in
networking can never be fully understood by someone who neither
builds commercial networking equipment nor runs an operational
network.
-- http://highscalability.com/blog/2013/10/2/rfc-1925-the-twelv...They never deliver from experience. They always bill though.
Security doesn't exist without the business and the business doesn't exist without security, but the business tends to trump security for the sake of features and convenience. It's a very delicate see-saw, and all you can really do is trying to run back and forth from side to side hoping that the other end doesn't hit the ground before you can get over there again.
Attitudes like yours don't help a damn thing.
The only people who deliver little value are the paid up consultants. When a full penetration and code review misses 4 purposely placed obvious vulnerabilities (by myself) they get told to fuck off. Application firewalls which are circumvented trivially. QoS solutions that don't work.
So far, four well known, well respected companies offering certification and testing have missed the holes and have been fired.
That's the problem: no delivery.
My attitude might be wrong in your eyes but I refuse to employ box tickers which is what the entire white hat side of the industry is about. Canned report, where's my cheque?
No seesaw other than a bent twisted one that sucks up cash in exchange for a half arsed job.
I may not be too versed in CloudFlare, but I didn't think they would be able to protect a service like SSH.
You can always pick an appropriate window of time, point to it, and say "See, there's a trend!". That doesn't make it so.
Github used to go down much more often than they do now - calling them 'increasing unreliable' really just shows that you have begun depending on it more heavily.
There is a value proposition involved - you can run your own source code hosting and anything else, but it costs money and time to do it. Especially if you need six nines of uptime.
If so, I wonder if they could counter this now by 1) implementing that 2) opening and publishing a not-standard port for login solely for that purpose 3) maybe moving that change-the-default port around if the DDOS shifts on to it.
Even if not-perfect they'd force the attack to spread resources.
personally I can't see why anyone would want to DDoS github unless they are just being an asshat.
Their parents didn't raise them very well if they don't realize that denying access to an important resource to tons of people is really, really lame.
[1]http://en.wikipedia.org/wiki/The_Million_Dollar_Homepage#DDo...
Mozilla has had the same issue: every so often someone tries to DDoS bugzilla.mozilla.org, causing it to get all slow and hard to use. :(
The issue tracker is not, unfortunately, but neither are most issue trackers.
http://bugseverywhere.org/ (my personal favorite, but there are 3/4 other options that you can look into).
Not only it does offer distributed bug tracking on the command line (without breaking your workflow), but it implicitly allows to isolate bugs to branches. You can fix a bug in a branch, and a subsequent merge of the changeset will automatically fix the current branch.
I don't understand why these projects are so underrated. In "early git times", distributed bug tracking on top of git was quite a hot subject. They solve many issues nicely.
Github might be a "nifty" viewer, and I do host projects on github for added visibility (by simply using a second push remote), but that's about it. I find "tig" and "bugseverywhere" to complement git nicely and work much better than any web browser could.
Many of the reasons for that will be very different from this attack on Github as there is no money in attacking Github. But one reason may be similar: Lack of imagination, or in other words stupidity.
We can't push latest bugfix to GitHub. Azure cannot deploy it. I cannot run bower_install on the project I would be working on in the meantime.
bower_install is annoying, yeah; it should allow for a backup location (s) to resolve dependencies. Maven allows people to configure multiple repositories, which are often mirrored against each other while hosted by vastly different parties; if one repo mirror is offline, there's a dozen others available, in a lot of cases.
For those components, github is a single point of failure.
http://blog.zerotier.com/post/58157836374/op-ed-internet-cen...
I heard that Go language can import packages directly from GitHub. So it means that they can't compile?
While GIT is distributed, working collaboratively with others still requires a central platform where everybody working on that GIT repo can connect. GitHub is a very convenient central platform.
To GITs credit; you can, with a little server know-how, set up your own git server and give all previous contributors access. However for a small downtime this could be overkill.
Back when my dad installed physical PBXes, the big ones that could be the size of a mainframe, uptime the biggest argument: they had to have reliability to five nines (99.99999%, if you don't get it). Then when cellphones first came out, everyone got lackadaisical about dropped calls. And overnight an entire industry worried about reliability "to five nines" changed, and "whatever, it's a new service, you've got to expect some difficulties."
The internet started with relatively low reliability. No web host I've ever seen has truly been able to achieve 99.999% uptime. And yet, when GitHub goes down under a "large DDOS attack" but still manages to maintain 99.85% uptime over the last month (with several DDOS-caused outages) everyone comes out of the woodwork to complain. After all, it isn't as-if hosting a massive service while keeping everything secure and running happily is an easy thing.
If you're tired of GitHub outages, then get a Bitbucket account, or host your own Git repository for backup. What serious developer, or service, would keep all their eggs in one basket if they really depended on the uptime of just one centralized service?
They probably haven't gone offline through a DDoS yet because they're just not that popular to warrant an attack but I wouldn't bet on it that Bitbucket would fare any better.
but they arent entirely honest about downtime.
sometimes they are down, ppl are tweeting it and status page is all green lights.
but still love em.
Are there teams that need to be in constant sync pushing and pulling multiple times an hour?
It's happened a couple of times. We moved to our own private server with forks of any dependencies we need.
Issues: hard to fix a bug you can't read about
Pull Requests: code review is a lot less fun without a tool for commenting, without something triggering your build server to verify each commit, etc
Releases: distributing builds to QA or users is all of the sudden more awkward than you're used to
It's not really about pushing and fetching code. :-)
Github: $200/month for Unlimited users and 125 private repositories.
If you're a team of 10 or less, have a few dozen clients and dozens more supporting libraries in a small company Bitbucket blows Github out of the water.
For the same $200/month Bitbucket also offers unlimited users (again, with unlimited private repositories).
I wouldn't call Github's pricing unreasonable. But I have learned to appreciate Bitbucket's service (they're really on top of things on their Twitter feed) and their pricing is lunch money for a day (as opposed to skipping lunches for a month).
Highly recommended.
Been with 'em for maybe a year now? Never had a failed push or pull. That's happened a number of times with Github but I wouldn't suggest it's been damaging to the business. Only a minor inconvenience at times.
So with your anecdote and my anecdote, we get to call this "data" now right? :-)
Plus: There are a bunch of decentralized issue trackers, can any of them sync with github? Is that possible with their api?
Last time I looked, their issues are not stored in git itself. This is something that has kept me from using their issue tracker for my projects as it encourages lockin.
Would each of us set up each other's internal IP addresses (192.168.0.101, etc) as remote repositories? Would each of us run a git repository on our own boxes? Or would we set one up on our own AWS box or something?
Edit: I might have misread the parent's comment. If CmonDev was referring to public availability, just a local repo won't do. It depends on who needs access to the code etc
Seems a bit pointless