China doesn’t like freedom. After the attack is done, I “trust” the various developers will be comparing checksums and going over the diffs of their code with a fine-tooth comb.
Here at SDA we use a reverse Great Firewall, I block each and every network block originating in China. 99% of the spam we used to receive originated from there, now it doesn’t.

> I “trust” the various developers will be comparing checksums and going over the diffs of their code with a fine-tooth comb.
A DDOS attack doesn’t really call for that. Unless I’m missing something?
Well, nice to see the Free Software movement has finally p1ssed off some apparatchiki. May they all develop boils.
Kevin, DDOS restricts access to the systems via conventional networking and paths. If you have a different pipe into the servers then denial of service won’t affect you.
Assuming that the attackers 1) just want to restrict access, 2) are behaving (using the network) like regular users, I think, is a mistake.
1) makes no sense from either a tactical or strategic mission plan.
2) if they have an alternate connection from previous intrusions then the DDOS is irrelevant except to block access to those who may want to fix the problem.
It makes more sense for the DDOS to be the feint rather than the thrust.
I would note too, the media loves their DDOS explanation.
GitHub hosts projects that mirror web sites that the PRC doesn’t like, and those projects are what the DDoS is targeting. This is in line with DDoS attacks the PRC has issued in the past to keep its own citizens from circumventing its information controls.
Sometimes a cigar really is just a cigar.
Don’t they get access to the server by attacking the TCP-IP stack with pings? I seem to recall several old bugs that would let people get in past the firewall just by overloading it. And as we know, many hosts don’t apply all the patches to all their servers, because its a full time job just doing that.
By the way. I looked into that Intel Edison thing. http://phantomsoapbox.blogspot.ca/2015/03/intel-edison-super-duper-small-pc-on.html
Could work as a suuuuuper low power Smoothwall box, but you’d have to add ethernet capability. I think it would shine as a wi-fi only device, it has wi-fi and Bluetooth built in. Pirate Box! h t t p: // piratebox.cc /
Add solar power and nail it to a fence post, instant dead-drop. Put a Pringles can antenna on it, instant invisible unfindable dead-drop with a really narrow broadcast window that’s really far away from your house. Might be handy, might only be uber-geeky. YMMV. ~:)
I bought one just because its freakin’ cool. It’s x86, so most Linux runs on it. I’m thinking GPS guided autonomous flying robot. Then I can have all the fun of CAD designing a suitably insane airplane to go with it. Can you say Nurflugel? Sure you can!
In any case, I think it would be *very* difficult to change a git repository without anyone noticing. The changes would either need to be added to the head in which case they would be very visible or people’s clients would complain trying to sync up.