Hacker News new | ask | show | jobs
by AnSavvides 4688 days ago
I do not understand why GitHub get attacked so often - honestly it's not like they are doing anything wrong, they are a fabulous service and the go-to place for most (if not all) developers for all sorts of projects, be it open source or in an enterprise/corporate context.
4 comments

Extortion, research, or for evil. Attacking Github may be an attempt to effect someone that uses it (Github may not be the direct target). What if it's possible to effect HFT trading.

---

We do know that they've been consistently attacked. Github has been unsuccessful in mitigating attacks.

Github needs to explain why these attacks are happening. What is being done to stop them. What has been done to stop them. And if they are different from previous attacks.

Didn't you just answer your question? It is the "go-to" place for most developers.
That doesn't really answer his question. Why would somebody want to inconvenience developers?
- Raising awareness of self-hosted alternatives

- Getting people to use BB instead

- Fake DDOS to get more companies to pay for github:enterprise

- Preventing a system upgrade in a company which has deployment relying on github

There are lots of potential ways to use it...

My guess would be attention and publicity. Targeting a technical, developer centered site is likely to require more "skill" as one would expect such a site to have their defenses ready for this. All the greater challenge. Secondly, every time this happens it causes quite a discussion on developer forums and sites such as HN. If you're seeking attention and "recognition" amongst technical people, what better site to attack?
Maybe a developer killed their parents?
Probably to disrupt businesses that rely on github or cause a service to function improperly causing a security loophole they can exploit.
The goal may be to potentially open up a new attack vector to steal code, some of which may contain secrets. This is pure speculation, but a definite possibility.
Maybe they want to disrupt developers working for a big bad company.
I bet DDos-protection companies (Dosarrest, cloudflare etc..) are happy to see this .. what's better than a new business potential
extortion, potentially.