The bottom line is that, much like the matrix, everything within China is still part of that system and can be weaponized by the Chinese government. So, be sure you never have anything from within Chinese IP address space loaded by your web pages or apps.
Baidu has no say in the matter. They could try and help Github by swapping to only serving their analytics scripts over HTTPS. Even then, this would only help once a large majority of existing websites that use Baidu analytics have updated their website code to point to the HTTPS URL. Until then the attack would probably still continue to work.
As always, majority of them simply don't care. Did many people stopped using Google after Snowden's leak on this side of GFW?
You can't unless it's an HTTPS request (and even then you may still want to be suspicious).
eg, Ars - http://arstechnica.com/security/2015/03/github-battles-large...