Pin-pointing China's attack against GitHub
blog.erratasec.com
blog.erratasec.com
When Sony was hacked a few months ago, the media couldn't wait to label it a "terrorist act" by North Korea.
I just now searched Google News for "github terrorism".
1. http://www.itpro.co.uk/security/24319/github-falls-victim-to...
2. https://grahamcluley.com/2015/03/github-ddos-attack/
That's all, even though the evidence appears more clear that the Chinese government is involved. Whereas North Korea's responsibility was in doubt. The silence speaks volumes.
But is "terrorism" even the correct word for this? When Saddam invaded Kuwait, was that a terrorist act? Consider this quote written by a Chinese military analyst 30 years ago:
those who take part in information war are not all soldiers. Anybody who
understands computers may become a "fighter" on the network. Think tanks
composed of non-governmental experts may take part in decision-making;
rapid mobilization will not just be directed to young people; information-
related industries and domains will be the first to be mobilized and enter
the war..
(From http://fmso.leavenworth.army.mil/documents/chinarma.htm)However, the Chinese may respond by claiming this was a preemptive defense. That GreatFire.com was designed to weaken their security and they were justified in taking action to protect the sovereignty of their computers. Haven't western nations done the same when they were threatened by terrorism or nuclear arms?
It seems to me that we have officially entered the era of a weaponized internet.
And GFW is indeed a WMD that must be stopped.
Maybe not "destruction" in the permanent sense, but given the damage that a DDOS can do (financially, at least), it would make sense to treat one as an attack on infrastructure.
Don't use that word. It's barely even a word any more, its become one of those weaponized magic symbols used for mind control. See also "freedom", "globalization", "sharing", "choice" and so on.
Instead, you can just use words like "murder", "destruction of infrastructure" and the like.
(Obviously you do need to use it sometimes, in an academic context for example. It's a tricky one.)
I'm not sure if that causes the word to be avoided in academic writing, I suppose largely yes (for its lack of any well-defined meaning) with some exceptions (probably by those who agree with the propaganda surrounding the word).
The only way to meaningfully use the term "terror(ism/ist)" in academic writing is to exactly define at the start of the paper exactly what you mean and also what you don't mean by "terror(ism/ist)". This may attract knee-jerks of "that's not what it really means/etc", thereby detracting from the main point of the paper.
The other problem is, that even if you nail down the definition, it's still contested because it's a very loaded term no matter how you turn it. The academic goal is objective description, not pointing out good guys and bad guys.
Once you get past that, next problem arises, which is that International Relations just isn't always a hard science (just like History is not). So even if you got a clear definition, and it's accepted that both parties are equally bad, it can still be quite fuzzy whether it's "really" terrorism, because the one guy did this, and the other troops such, but then the guerillas, however it was the rich families that something or other, and Ted supported George, while Bill's family lived on the land for generations, blah blah bla etc. I really suck at history, it's just confusing.
All in all it's just more accurate to describe who did what, and if you want to describe something "terrorism"-ish, it's better to just describe reasons behind the attacks, the psychological goals, and psychological effects certain attacks had on the population, etc. Basically just say what you mean (even if they're theories) and state the facts, but avoid the loaded term.
Nope, the State department has yet to respond.
China used 1% of the available traffic from a single CDN. Their choice of target might just have been randomly picked from low priority list for the dual purpose of sending a political message.
If decades of continuous trade deficit and serious attacks on places like Los Alamos go under or unreported, don't hold your breath for GitHub.
Of course if it were North Korea (or Iran) it would be headlines.
the era of a weaponized internet
Is HN turning into Fox News now?
http://en.wikipedia.org/wiki/ARPANET#Misconceptions_of_desig...
Even if it were true, designing something to withstand attack doesn't make it a weapon. Is a kevlar vest a weapon?
In short, I believe the Chinese government knows what it is doing, while the Indian government does not.
That was when the company transferred our work, and the test servers, to India. We shipped the machines, and to send them, they had to be packed on pallets. The pallets were wooden. For Indian customs bureaucracy, I had to arrange a paper called phytosanitary certificate, which states that the wood has no bugs.
The Chinese government will happily block any site they want to and they have little/no regard for the popularity or usefulness of the site in question, and often they will block popular foreign sites to help copycat local versions thrive.
Off the top of my head they block Facebook, Twitter and Youtube entirely and Wikipedia selectively (used to be permanently also). I can tell you they don't care about blocking GitHub.
The also have the ability to dynamically block sites based on page content rather than just entire domains, so it would be perfectly feasible for them to block just the project pages and not the entirety of GitHub.
Before long time ago, people hosting tons of anti Chinese government stuff on Google, especially Common Storage Service, yes people say China wouldn't dare block Google.
LOL
I don't think the Indian Government's competancy in IT (and many other things) come close to that of China; but hey atleast we don't have a muzzle over our mouths (that's partly a lie).
Wasn't the "ban" actually a DNS entry removal ?
So when I get a packet with ttl so small that won't survive long enough to reach the target, instead of altering, I just leave it along. So the probe will never know where I am in the route.
The experiment in the article required trusted trust of packets destined for the great wall passing through US infrastructure. That this infrastructure can generally be considered neutral is no guarantee that it was in this case. Any router or switch can use arbitrary tables and conditional logic on any packet. The purpose of the experiment was prosecuting a particular suspect not arm's length analysis.
A friend of mine runs a honeypot service that uses servers all around the planet, someone like him would be in a good position to run analysis like this.
On the other hand, I don't think it's really necessary to prove with technology that the 中國人民解放軍 is behind this. Diplomatic logic is sufficient. The behavior is simply an internet equivalent to jamming the Voice of America.[1]
Github is broadcasting. The 中华人民共和国 has a sovereign's policies regarding broadcasting. The 中國人民解放軍 executes those policies. Github operates with a business model that ignores sovereigns at its own peril. Calling one sovereign for aid when dealing with another sovereign also carries peril.
Allowing political content in an online community always comes with the risk of trolling and flamewars. A hands off editorial policy only means Github hasn't made a tough decision about what the Github community is not. Decision day can only be put off so long.
Now of course those repos are intended to circumvent that but once someone has them they are out of reach of the GFW. So blocking those urls at the GFW would seem to be all that's really needed.
Tools like these should be accessible from as many places as possible.
1. 中华人民共和国 has laws.
2. 中华人民共和国 is well connected to the internet.
3. 中华人民共和国 can project its interests
around the world easily in rather nasty ways.
4. 中华人民共和国 can project its interests from
within its borders.
5. 中华人民共和国 has an interest in controlling
commerce within its borders.
I believe this is an act of foreign policy, not domestic. It's not about unplugging citizens from the internet. It is about achieving some parity with other state level actors in regard to what is and isn't allowed on the internet.中华人民共和国 's interests are orthogonal to those of the US and UK. It is not so much interested in the internet as an organ of a surveillance state or as an alternative source of foreign intelligence in lieu of boots on the ground.
The mechanics of the attack are entirely within the realm of sanctioned internet behavior: visiting a site places javascript in the browser without explicit approval of the end user. The javascript may do something not in the user's interest. The javascript may generate unnecessary internet traffic. The purposes for which the javascript does so are solely the purposes of the site injecting it.
The great wall comes with terms and conditions.
I don't consider myself subject to those terms and conditions and attacking github affects me in a very direct way. As such this is not acceptable and I hope that sufficient work will go into un-ambiguously determining who did this.
Consider it a DCMA takedown notice.
For the same reason I use "Github" instead of saying "distributed version control ddos'ed" or "git unavailable on the internet". It picks out a more precise set of attributes and methods and limits the likelihood of slipping into anthropomorphisms such as "The Chinese." In particular it limits the range of what is historically relevant: ground combat against the US Army in the 1950's is, against the USMC in 1900 not so much.
Since I believe this is a matter of foreign policy and international trade, the sovereign and the corporation are the appropriate level of abstraction for analysis and language should reflect that in order to be clear.
Was it the 中國人民解放軍 or the 中华人民共和国?
That Hobbes underpins pretty much any political discussion in the Anglophone world even if not explicitly acknowledged is just a bonus, and I use the terms in the sense of "is" not "ought".
That the Hobbesian model maps onto the political traditions of the Middle Kingdom and futball with little friction suggests the pervasiveness and universality of little '\p` politics.
Not sure what you mean by "sanctioned" here. Technically possible? Yes. But also abusing and perverting the most important medium of our age.
The internet largely works BECAUSE of trust and cooperation and BECAUSE actors chose to not fuck with each other. If China truly is behind this I have half a mind to just cut them entirely out, except in a way that is exactly what they want and figuring out how to maintain the positive effects of said internet on democracy and free speech is worth the trouble.
There is significant evidence that the US, UK, and other state actors are fucking with people. That it is not in the same way 中华人民共和国 is is a relevant fact to some people and hair splitting to others. Likewise the trend in 中华人民共和国 toward greater democracy and in the US, UK and other nation states toward greater oligarchy is a relevant fact to some and hair splitting to others.
Free speech and democracy only exit so long as the sovereign believes they will keep the peace. The US, UK and other sovereigns willingly restrict free speech in favor of intellectual property interests in recent days. They have always been willing to curtail the trappings of popular sovereignty to keep the peace. That's the social contract.
The internet has grown where and in directions that coincide with the interests of sovereigns. Sometimes that means acceding to popular demand. Sometimes it doesnt (e.g. Napster).
Using my custom http-traceroute, I've proven that the man-in-the-middle machine attacking GitHub is located on or near the Great Firewall of China.
Although suspicious, it seems one would need to know a lot more about China Unicom and their infrastructure to say this conclusively.
Again, I have not looked at this in detail yet and probably won't have time for a few days. I would welcome a discussion on this point.
edit: above may be imprecise. I went back and read the original more closely. they note that if they artificially drop an injected packet, it doesn't get resent (and hence the conclusion that it's man on the side), but they don't mention whether they get the original packets or not. If something is blocking the original baidu packets, it would have to be in the middle, not just on the side.
It is possible that the cache is also injecting the attack, but I don't actually see anything that suggests this from the data in the article.
If it was a hack, surely China Unicom should have fixed it by now?
Perhaps they don't even know something is going on?
Correlating the circumstantial facts that China has a giant firewall, the content being blocked is getting around China's firewall, and an attack came from somewhere deep in one of China's largest backbone providers, does not make an 'extreme likelihood'; it makes a weak correlation. Likelihood requires reviewing known outcomes to determine a likely result. What other known evidence of specifically these three behaviors by the Chinese government are you basing this conclusion on?
> This is important evidence for our government.
You've taken a massive leap in logic from a machine inside China manipulating global traffic to attack servers in the US, to conclude that it is more likely to have been the Government than anyone else. This is exactly the same as saying any attack originating from the US which appears to be related to US interests must be from the US government. If this was the basis for how we concluded all investigations into illegal actions, anyone who 'looked like' they did it would be found guilty, sans evidence. That may be how other nations' justice system works, but not ours.
Furthermore, in no way is either Github or Baidu's analytics considered 'key US Internet infrastructure'. I mean, Git is even a decentralized system - people can still get work done if it's down!
This is not evidence of the Chinese government's complicity, and pretending it is creates a dangerous logical fallacy that could improperly shape public opinion.
[1]: https://rdns.im/the-pirate-bay-north-korean-hosting-no-its-f...
I was under the impression that this was a man on the side attack, so they'd sent a bogus SYN-ACK back to you the moment that they saw a SYN. Theoretically, you should still only be dealing with one RTT.
>(and if there was concern, appropriate amounts of random delay and noise could be added).
I don't think China cares if it gets traced back to them.
No they don't, and when time arrives, they deny whatever the accusation is, and claims it's a defamation.
"On your second question, it is quite odd that every time a website in the US or any other country is under attack, there will be speculation that Chinese hackers are behind it."
http://www.netresec.com/?month=2015-03&page=blog&post=china%...
It seems a bit of a stretch to say that Github is "key US Internet infrastructure"...
Disclaimer: I'm not sure what actual usage stats are like for GitHub.
But if github were down for two months, the nature of git suggests that deployment for those many individual projects would shift either to the originators' infrastructure, or some other aggregating service.
There is a lot riding on GitHub that developers use. Hell, even closed-source companies sometimes use empty GitHub repos so they can use Issues for openly available tracking.
The fact that a request with a TTL smaller than 12 does not trigger a response does not mean the responder is the host after 12 hops. Assuming none of the previous hosts misbehaves (they could be increasing or at least not decreasing the TTL) you can only conclude that it is none of the later hosts, but it can still be any of the previous ones.
That leaves you with Comcast AND China Unicom hosts and, considering that the replies you see in the traceroute results can easily be spoofed, it can be any third party as well.
Possible scenarios include (I don't say they are more likely):
1. Comcast is producing the responses, but only does so if the request TTL is large enough to make you blame China Unicom.
2. China Unicom hands the packets over to a third party after just a few hops in their backbone. The third-party sends ICMP Time exceeded messages looking like they are from other China Unicom hosts to make you blame China Unicom.
Conclusion: This is either an obvious attack from within the China Unicom backbone OR a more sophisticated attack where the attacker wants to a) hide his identity and b) blame China Unicom for it (I can't think of a scenario where b) would be a by-product and not on purpose).
Just saying. The sentences in the post that include the words "prove" and "proven" are simply wrong.
Pin-pointing China's attack against GitHubI am sure they have a private key of some of the CAs shipped with major browsers lying around somewhere...
@collinrm I just took masscan, changed the HTTP request,
then tweeked the code to generate a small TTL.
Source: https://twitter.com/ErrataRob/status/583433175302479872I'm sure computers are now mainstream enough that it would matter for any country to put cyber warfare as a key strategy. The US and the west dominate through open trade and easy communications and free speech. Maybe that makes China vulnerable, and they're trying to defend themselves economically.
You can accuse China all you want, but if you're an american, it's harder to listen to those accusations.
(It could be by some party outside of China, or by some group inside of the Chinese government that does not have an official mandate to use it for things like the Github attack)
This GitHub business looks more and more like a false flag operation.
The more that comes out and the more silence there is from the Chinese government the less it looks like a false flag operation. Usually the victim of a false flag operation (China in this case, not github) would be very adamant about its non-involvement and would work very hard to expose the originator.
A parody is just that, we're talking about a several day long real attack here.
And if you read that article you'll see Beck sued to get the domain. So it's not like he ignored it, and besides it was obvious from the beginning that he wasn't the one that registered the domain.
I mean they've Tibet for the trump card after all; Cyber-attacks are kid-stuff.
(P.S: I sympathize with the Tibetans; but there is really no political will to resolve this, not in the US, not in EU, not in India).
Besides, I'm sure it is easy for them to manipulate US senators by giving them campaign funds.
That's not really a defence. They could easily be that stupid, bureaucracies tend to do extremely stupid stuff when looked at from the outside but every cog on the inside thinks that its action makes perfect sense.
> This Github DDoS has got to be the work of someone trying to frame the Chinese government.
Evidence?
> Has anyone considered that angle ?
Sure, but so far the evidence is that that is not the case.
If it is someone trying to frame the Chinese government I'm sure they'll tell us all about it soon.
If this is Chinese doing, the likely ones responsible are the Chinese Intelligence, not their bureaucracy.
> Evidence?
Occam's Razor. I find it hard to believe that a society with sufficient level of sophistication to obtain $9 trillion GDP[1] would 'accidentally' go on to declare cyber war on US. Especially considering the fact that the attack itself was pretty sophisticated.
[1] http://en.wikipedia.org/wiki/List_of_countries_by_GDP_%28nom...
Intelligence agencies are bureaucracies. Some are more efficient (less wasteful) than others, but in the end, intelligence work is seldom about secret agents driving Aston Martins. Most of it has always been paperwork. Paperwork is nowadays in electronic format. I don't think the Chinese intelligence agencies are an exception.
1) the attack is perpetrated by the entity the evidence suggests and
2) the attack was prepetrated by another entity who cleverly used infrastructure of the first entity to frame them for it,
applying Occam's Razor would suggest situation #1 in lieu of evidence to the contrary.
On the other hand, why would anybody go to this length to frame to Chinese government? What would they try to accomplish? Obama sending a strongly worded letter to the Chinese government?
We could also speculate from the angle that the officers in charge of making these decisions are not tech-savvy themselves (or at least not to the level that they might realise just how traceable these attacks), which isn't a huge assumption to make when you look at how incompetent many government officials are who have serious influence over technology policies (eg http://www.bbc.co.uk/news/technology-23437473)
So anyway, my point is it's better to look for a little evidence to support a hypothesis rather than blindly speculate.
the overwhelmingly most likely suspect for the source of the GitHub attacks is the Chinese government.
Why would the "Chinese government" carry out an open attack against an american company for absolutely no potential gain at all?
Do you really think they are stupid enough to believe such an attack could remove these two software packages from the internet?
The fact that this attack doesn't pass even a most cursory risk/reward analysis.
Anyone with the technical smarts to carry it out must be well aware that there is zero upside potential for China. The targeted projects are not gonna disappear, github is not gonna disappear.
All possible outcomes are negative; The targeted projects get extra media attention (Streisand effect), the "Cyberwar" narrative in the west is fueled (cf. this HN thread), in the worst case there could even be a minor diplomatic quarrel with the US.
What do they have to win here?
Github is up and running after all. Both targeted projects are online:
https://github.com/greatfire
https://github.com/cn-nytimes
Looks like if you want to mess with China then all you have to do is put your material on Github. You think that is the lesson China wanted to teach the world?Lets not forget this wasnt an easy thing for github to handle. Their service still isnt running at 100% normal. Not to mention the cost burden they're currently dealing with.
Was there any doubt about China's ability to blast sites much bigger than Github off the internet to begin with?
They're the second largest economy in the world. They don't need to play painfully obvious MITM tricks on their own infrastructure to carry out an attack - which then doesn't even have enough oomph to make a dent on a large but probably not particularly hardened site.
Lets not forget this wasnt an easy thing for github to handle.
That doesn't change the message that this random, half-assed neck-slap sends.
If this was really done by Chinese authorities and if I was a Chinese dissident then I'd be thrilled rather than chilled. Who knew keeping my stuff online could be as easy as uploading it to Github!
Do you really think anyone concerned with these things (activists, VPN providers, companies doing business with China) needed a half-assed, unsuccessful Github attack as a "deterrent signal"?
Interestingly, this also gives China more bargaining power in its negotiations with the US about "cyber" issues
Why would the US Government be concerned about "chinese attackers" that apparently can't even take out a civilian top100 website?
Interestingly, this also gives China more bargaining power in its negotiations with the US about "cyber" issues
You mean they will offer to stop "pretend attacking" american companies, and the US will then make concessions out of gratitude?
The potential gain is that they can extend this capability (and chilling effect) to GitHub and other sites that aren't under the sovereign control of China. Nobody wants to go out of business just because a user uploaded a file which is politically controversial in China. Now every company will think twice and come up with some weaselly reason why they can't have text files about Falun Gong or whatever.
You mean like Github did in this very case? Except wait, they didn't.
So who is this "every company" that will now "think twice"?
To give all those conspiracy theorists a clear picture, what really happened is merely the scale of problem you have never worked on or dreamed to be working on outside China.
This happened year ago when a Chinese state funded train ticket booking website accidentally deployed to production with a opensourced Javascript vendor file still linked to github. And first day that site went live, 30 billion visitors tried to secure a ticket for coming Chinese New Year, when took down github for a good while. Yes it was a DDOS attack from China, by train ticket buyers.
Last November, Chinese online c2c marketplace TaoBao.com, saw 16.7bn transactions in one day, with more than 1 billion CNY settled in a minute. If any of the web dev responsible for even a small promotion page left a link of cool jquery plugin from GitHub, you could have written another holy crap evil government attack post here.
Why is the code still running a week later? It doesn't take that long to find the offending server/s code and remove it. Especially as it is making the Chinese government look bad, there would be added incentive to fix this pretty quickly.