我们正被攻击

我们受到了攻击,我们需要帮助。

像是回应最近华尔街日报(WSJ)的故事似的,我们经历了有史以来第一个分布式拒绝服务(DDoS)攻击。这种攻击是通过发动向洪水一般的大量垃圾请求来使网站崩溃 - 就在这篇文章在撰写的时候,每小时有大约26亿次请求。一般的网站根本不具备能力处理这么大的流量,所以在濒临崩溃后不得不被迫下线。

这种攻击是非常野蛮的,甚至可以说是暴力的。攻击者只有在一般的攻击方法都不奏效时才会采取这样极端的手段。

我们无法防御这种规模的DDoS攻击,所以我们不得不寻求帮助。

一些背景资料:

  • 攻击开始于3月17日,我们每小时都要收到高达26亿的请求,这是大约正常水平的2500倍以上。

  • 这种攻击影响了我们所有的镜像网站。虽然我们已经公开谈论过我们的使用“依附的自由”和手机APP来解放被中国当局封锁网站,华尔街日报的报道也明确这样的策略是如何奏效的,以及它如何成功地将未经审查的内容引入中国。我们已经解封了包括博讯,德国之声和谷歌等被中国封锁的网站。

  • 我们并不知道这次攻击的幕后黑手是谁。然而,攻击恰逢我们的组织在过去几个月中压力越来越大的时候。中国网信办(CAC)公开宣判我们是“由海外反华组织成立的反华网站”。我们也知道,CAC对我们的合作伙伴施压来使他们停止与我们合作。最近,我们还注意到,有人曾试图冒充我们来截取加密的电子邮件。

  • 上周,一个总部设在巴黎的无国界非政府组织的报道,用我们的“依附的自由”方法来疏通世界各地的九个网站,其中包括两个对中国比较重要的:明镜新闻和国际西藏邮报。

我们需要您在以下几个方面的帮助:

  • 巨大的请求数致使我们的带宽成本已经飙升至30000美元一天。我们正在使用亚马逊的云服务,我们仍不确定亚马逊会不会额外计算这笔费用。如果他们会,我们的服务将会显著的紧缩。

  • 我们需要像亚马逊这样的公司站在我们这一边,尤其是言论自由的一边。我们需要你告诉亚马逊,你认为言论自由是一个非常重要的问题,并且亚马逊作为全球互联网的领先推动者,在获取信息的上起到很重要作用。

我们已经升级到更快的服务器,并使用一些技术来管理负载,现在暂时好一些了,但我们担心这次攻击随时可能会更加激化。我们需要帮助来处理这些事情。如果你有这方面的人才,请联系查理·史密斯或通过Twitter联系我们。

评论

更多博客文章

订阅 email
显示 博客 | Google+ | Twitter | 全部 的消息. 使用 RSS 订阅我们的博客。

星期一, 6月 10, 2019

苹果审查中国西藏的信息

苹果在涉及西藏的审查方面有着悠久历史。 2009年,据计算机世界网透露 ,与达赖喇嘛有关的几个应用程序在苹果的中国区应用商店中不存在。这些应用的开发者未收到他们的应用被删除的通知。当面对这些审查制度时,苹果发言人只是说该公司将“继续遵守当地法律”。

2017年12月,在中国的一次会议上,当被问及与中国当局合作审查苹果应用商店时,蒂姆·库克 宣称

“所以你的选择是参与进去,还是站在局外,吼叫着事情应当怎样?我自己的看法非常强烈,你得进入赛场,因为没有任何东西会从局外发生改变。"

自苹果公司首次因与中国当局合作以遏制已被边缘化的声音而被批评的十年间,情况发生了什么变化?苹果继续严格遵守中国当局的审查令。蒂姆库克什么时候会期望他的公司能帮助在中国带来积极的变化?

根据生成的数据 https://applecensorship.com,Apple现在已经审查了在中国应用商店中29个西藏的热门应用程序。关于新闻,宗教研究,旅游甚至游戏的西藏主题应用程序正在被苹果审查。最下方附有完整的审查应用列表。

“苹果的领导力隐藏在他们审查应用程序以遵守模糊的'中国当地法律'的借口,但他们的行为缺乏任何透明度。通过从中国苹果应用商店删除藏文和其他许多应用程序,苹果阻碍了藏人获取信息和自由表达自己的能力,这是国际法下的一项基本人权。“ TibCERT(西藏计算机应急准备小组)的响应协调员Dorjee Phuntsok说道。 他们与GreatFire合作对被屏蔽的应用程序进行了分析。

   2019年1月,GreatFire推出了applecensorship.com。在那时,GreatFire联合创始人马丁约翰逊指出:“苹果公司在其透明度报告中没有分享有关应用商店审查的信息 - 该项目强制透明度。蒂姆库克可以随心所欲地说苹果在中国做了或没有做什么,但 applecensorship.com 提供了可以实际看到苹果实施审查原始数据的途径。

分析苹果在中国审查的iOS应用程序

有许多应用程序由藏人或为藏人制作,苹果正在审查中国区应用商店中的许多应用程序。了解某些应用程序被阻止的方式和原因以及这些决策背后的基本原理非常重要。为了解这一点,TibCERT(西藏应急准备小组)对在中国应用商店中被审查的藏文应用程序进行了分析。该研究使用关键字搜索藏文应用程序,然后使用GreatFire提供的应用程序审查平台。

TibCERT分析了119个以藏语为主题的iOS应用程序。使用“西藏”,“藏人”,“达赖喇嘛”,“佛教”,“藏传佛教”,等关键词搜索苹果应用商店时,可以找到下面列出的应用程序。这些应用程序分为五大类:“宗教或文化”,“媒体/政治”,“娱乐”,“工具”和“教育”。

星期四, 6月 06, 2019

重点关注苹果在中国审查实践的报告

最新的 数字版权企业责任指数排名 就公司和政府需要做些什么来提出建议,以改善全球互联网用户的人权保护。数字版权排名(RDR)旨在通过为公司尊重和保护用户权利制定全球标准和激励措施,以促进互联网上的言论自由和隐私权。

在他们的2019年责任指数中,RDR着眼于24家世界上最重要的互联网公司在言论自由和隐私方面的政策,并强调了那些尚需努力和已经取得改进的公司。 RDR指出:

透明度不足使私人政党,政府和公司本身更容易通过网络言论滥用权力,并规避责任。

特别是,该报告强调了苹果如何滥用其网络言论的权力,并在中国指出这一点。根据该报告,苹果公司在面对政府当局提出的要求时,并未披露其从App Store中删除内容的数据。

虽然[苹果]披露了有关政府限制帐户请求的数据,但它没有披露有关内容删除请求的数据,例如从苹果应用商店删除应用程序的请求。苹果公司对其影响言论自由的政策和做法讳莫如深,这让它的排名低于此类别的所有其他美国公司。

该报告为政府提出了明智而感性的建议。然而,这些建议还强调了与中国政府进行这些讨论是多么的困难。

RDR 建议政府要求公司的透明度并保持透明度。中国当局采取相反的做法 - 他们不希望在这些问题上保持透明度,因为它突显了他们不希望公众了解的信息。当局不希望公司透明,他们可能直接指示Apple不发布他们正删除的内容列表。

苹果可能真的认为他们必须遵守中国的法律条文。或者他们也可能愿意分享有关App Store中被审查内容的信息,但有碍于被中国当局束手束脚。苹果还可能会利用这种情况作为他们打击中国言论自由的掩护。无论Apple的真实动机如何,透明度都能够并已经被强加给他们。

在2019年1月,GreatFire发布了 applecensorship.com。该项目监控Apple在公司运营的每个市场中对App Store的审查。应用程序的可用性测试由网站访问者进行。截至今天,用户生成的测试已经确定了 超过1100个 在中国应用商店中不可用的应用。在中国受审查的应用程序包括那些涉及宗教,新闻,隐私和翻墙的应用程序。通过审查有助于规避审查限制的应用程序,苹果确实的让中国人无法自由访问信息。苹果的中国用户或许认为他们买到的是一流的设备 - 但可以肯定的是,该公司将他们视为二等信息公民。

RDR建议苹果对言论自由的限制保持透明,并公布有关公司因政府要求而删除内容所采取行动的数据。我们邀苹果审核我们在 applecensorship.com 上公开发布的数据,并根据中国当局的指示突出显示已删除应用的情况。

星期四, 11月 30, 2017

关于在中国苹果商店被审查的那674个软件

苹果对中国区的审查行为敞开了大门 - 但这似乎只是冰山一角。

星期二, 5月 23, 2017

Is China establishing cyber sovereignty in the United States?

Last week Twitter came under attack from a DDoS attack orchestrated by the Chinese authorities. While such attacks are not uncommon for websites like Twitter, this one proved unusual. While the Chinese authorities use the Great Firewall to block harmful content from reaching its citizens, it now uses DDoS attacks to take down content that appears on websites beyond its borders. For the Chinese authorities, it is not simply good enough to “protect” the interests of Chinese citizens at home - in their view of cyber sovereignty, any content that might harm China’s interests must be removed, regardless of where the website is located.

And so last week the Chinese authorities determined that Twitter was the target. In particular, the authorities targeted the Twitter account for Guo Wengui (https://twitter.com/KwokMiles), the rebel billionaire who is slowly leaking information about corrupt Chinese government officials via his Twitter account and through his YouTube videos. Guo appeared to ramp up his whistle-blowing efforts last week and the Chinese authorities, in turn, ramped up theirs.

via https://twitter.com/KwokMiles/status/863689935798374401

星期一, 12月 12, 2016

China is the obstacle to Google’s plan to end internet censorship

It’s been three years since Eric Schmidt proclaimed that Google would chart a course to ending online censorship within ten years. Now is a great time to check on Google’s progress, reassess the landscape, benchmark Google’s efforts against others who share the same goal, postulate on the China strategy and offer suggestions on how they might effectively move forward.

flowers on google china plaque

Flowers left outside Google China’s headquarters after its announcement it might leave the country in 2010. Photo: Wikicommons.

What has Google accomplished since November 2013?

The first thing they have accomplished is an entire rebranding of both Google (now Alphabet) and Google Ideas (now Jigsaw). Throughout this blog post, reference is made to both new and old company names.

Google has started to develop two main tools which they believe can help in the fight against censorship. Jigsaw’s DDoS protection service, Project Shield, is effectively preventing censorship-inspired DDoS attacks and recently helped to repel an attack on Brian Krebs’ blog. The service is similar to other anti-DDoS services developed by internet freedom champions and for-profit services like Cloudflare.

使用 RSS 订阅我们的博客。

评论

You deserve that for been criminals to the free Internet.

Regarding the DDoS attack - please consider using Cloudflare as a caching layer for your website - they are good when it comes to defending against that sort of attack.

+1 you should sign up to Cloudflare. Let them soak up the attack so you only pay for legit requests.

If you use CloudFlare you'll have to release all your current AWS public IP's and get new ones. Also AWS does give you a layer of protection but it is manual and maybe hard to maintain if the DDoS is from zombies or botnet.

For instance, CloudFlare has a program specially for website that empower freedom speech and I think it won't cost you a penny.

Please sign up for CloudFlare. Even at $200/month you will get significant benefits and DDoS protection, they are REALLY good!

+1 for CloudFlare

这种ddos是对着url进行攻击吧。。amazon的url感觉都是随机生成的,写个api一小时生成一个新的url。。如果是自动抓取就像上次干掉全国dns那样把攻击引导百度cac。gov.cn之类的吧。。。(没用过amazons3不清楚能不能换url)

Sent you an email, let me know if you need help setting Cloudflare up. If nothing else it's a great place to start.

You should look at CloudFlare. They are quipped to handle this sort of thing and they are definitely less than $30k per day!!!

Cloudflare is 'throttled' in China as with all the other CDN's.
Any requests to a CDN based resource are effectively denied.
Think again.

Cloudflare IP addresses is completely blocked in China. Using CF is not a good choice at the moment.

Create an Avaaz campaign to help support your conversation with Amazon? Might be easier than Twitter for a lot of your readers.

Consider deploying on premises protection to defeat the attack at the very edge of your network. @Corero allows for good traffic to pass, while mitigating the DDoS attacks in real-time.

Time to start naming names.

The president of China is Xi Jinping and everyone should know his name. Nothing in China happens without his consent.

Xi Jinping, Xi Jinping, everytime you hear about censorship in China you should think of Xi Jinping. Everytime you write about censorship in China you should make sure and write his name, Xi Jinping.

Rant over, start naming names people.

Use Fail2ban. No cost, easy to load and protects against several forms of attacks. http://en.wikipedia.org/wiki/Fail2ban

You can get a similar effect to Cloudflare (unfortunately minus the benefit of their massive infrastructure to absorb traffic) if you install mod_evasive (Apache module) and tune your config a bit. See the DDOS section in the included link, specifically lowering your timeout and keep alive timeout. Also turn down MaxRequestWorkers if your server is spawning too many processes. With mod_evasive, specify the DOSSystemCommand to ban the address using your firewall, for example, with iptables something like:
iptables -A INPUT -s %s -j REJECT
mod_evasive will substitute the %s for the source IP.

Check out:
mod_evasive: https://www.linode.com/docs/websites/apache-tips-and-tricks/modevasive-o...

Apache config: https://httpd.apache.org/docs/trunk/misc/security_tips.html

consider moving your hosting to ovh or online since they do not limit you on traffic. and they are cheap. and they offer the best ddos protection there is!

You may consider explaining to amazon that you are under attack and want the traffic dropped upstream.
Amazon should be able to do better than letting the host application absorb the requests (If they can not, I am rather disapointed).

Kim John Coon's suggestion above to try and identify and filter the abusive traffic with iptables will help take the load off your server.

安装360的用户普遍感觉电脑变慢,天下有免费午餐吗,360有可能利用用户电脑进行云计算或者ddos攻击

I see that the effected services have been blocked to those outside mainland China. Good move to counter this attack, well done.

Time to start naming names.
The president of China is Xi Jinping and everyone should know his name. Nothing in China happens without his consent.

happy mothers day quotes
mothers day quotes

Just get a firewall. Cisco if it's that bad. Or just use a dedicated ESF server for you're public ip and you'll be protected and it's got a very fast learning curve. We've been fending of attacks every minute from around the world with ESF. You'd be surprised how good this FW is and you don't even need a license.

now we are under attack in AU

blocking, dns fudged to show fake errors, searchines and those widgest they have on so many other websies suddenle become full of outright malicious code .. and that gets worse and worse, even the operating systems (all of them) spit out fake error messages ... some stuff like that even in linux source code .. all operating syste, agffected and the symptoms are the same .. files mysteruiously get deleted (even text files and code), sites get blocked and things reguce to cionnect to local networks unless that is connected to to the outside .. everything suddenly wanting centralised "cloud" logins, and a lot of nasty code snuck into operating syustem updates .. seems like in the last month or so its suddenly malware everywhere on EVERY OS ..
and try searching for a clan install iso of anything and you are quickly under attack from just about everything out there ... ... seems like not just one corrupt corporation but a consortium of the most corrupt corporations on earth and ALL of it seems to be trying to bully people into handing over admin of their OWN pc to unknown third parties i"in the cloud"

THERE IS NO WAY IN HELL I AM GOING TO TRUST SUCH OBVIOUSLY CORRUPT COMPANIES AND NO WAY IN HELL I WOULD TRUST SOMEONE TRYING TO FORCE ME TO TRUST THEM..

"management" stops at the front router .. that the way it will STAY ..

do not EVER give in to those creeps - DO NOT BUY THEIR STUFF - make sure everyone knows

yes it IS getting into OS updates ..
in open source systems have a look! .. thetre are error messages designed to MISLEAD the users - obviously something malicious got in .. and where theres no siource code the effect is the same top - its in EVERYTHING that was updated over the last couple of months.

now the government here even officially passed a bill to fo censorship! .. and its happening all over the world .. same stuff about "metadata retention" .. and they talkk about usage data.. NO - its obiously a LOY more than that if they are putting code on every user pc, deleting their data witrhour warning, and even the error meressages lie and every attempt to get rid of it by trying to find a frees clean distro iso met with attack after attack .. javsript everwhere not just tracking bout way more malicious .. attacks from every direction .. never seen anything this bad... and anty info seems impossible to find ..
censorship everywhere

never would have thought it woyuld become like that over here.. but looks like the same talk from politicians, the same trolling and sloganising from corporations

probably not hard to giess what went on atr those secretive "trade talks"

this looks like planet scale totalitarism .. corruuption fgone mad ..

isd there anything left that is safe? .. how will anyone be abloe to da anyithing if you don;t know id that file will get deleted just after you save it!!!!

and its obviously for censorship , not "copyright" or any other broken nonsense .. whate else could it be if text files and code set it off even more than music or video and it doesn't seem to care whether you made it.

seems like its the worse malweare ever seen coming from every directopm at the same tind along with it a lot of suspicious trolling and "social engineering"

all I can find is the occasional leftover hint ... news items explaining anything rare (probably censored)

MAKE SURE THEY DON:T GET A SINGLE CENT.

it looks like a consortium f the most corrupt corporations on earth have been changing the law in every counltry precendent by precedent over the last decade and syicking their dirrty fingers into everything.. not it sems the have a leash on nearly every government and their security agencies .. the most corrupt corporations on earth - and those obvously stacked meetings of so called "standards bodies" in recent years .. yes they are even hijacking network protocols...

.. probably not hard now to guess what went on in those secretive talks .. with all that happening since then

no MANAGEMENT STOPS AT THE FRONT DOOR AND THERE IS NO WAY IN HELL I WILL LET THEM GO ANY FURTHER.

what sort of idiot would want to trust lowlife like that with anything?

by now they should know what I think if their "cloud" bullshit!

no .. no way
I would want let third party "management" run by people so corrupt near any box let alone break things, delete data and try to destry my life! .... I will fight in anyt way I can to keep those
creeps out.

it might help if there was a still a way to communicate with anyone without anything important or even slightly interesting disappearing .. but nonetheless they are not getting in my jouse .., I never wanted to be anyones enemy and won;t be selling out to their ways and hurtunbg anyone .. but I sure as hell won;t lert them control anything here!

so angry I can barely type...

don;'t want to even think about what other people might do .,.

no i despite how bad the furureits looking I just won;t put up with it ..
btrining that inot my house makes it *personal* and we must make sure EVERY company or person who helped them attack us NEVER EVER gets a cent out of ANYONE

yes - Im angry..

intersing though - if this were a file on my h
no i despite how bad the furureits looking I just won;t put up with it ..
btrining that inot my house makes it *personal* and we must make sure EVERY company or person who helped them attack us NEVER EVER gets a cent out of ANYONE

yes - I'm angry..

and don't wan't any "management" crap destroying my life .

and I never try to hurt anyone.. I'm actually still human, unlike those creeps

Keren bingitz sist, makasih sharingnya. Ini artikel yang saya cari
selama ini. Informasi seputar web hosting yang sangat bermanfaat.
Kalau boleh tulis juga bro tulisan menegani hosting murah dan olshop.
Ane mau ngerti banget soal itu.

Look at my blog post - hosting usa murah

Ulasan bermanfaat soal web hosting ini baru pertama kali saya baca.
Keren sekali dan penting. Setiap orang yang pakai ataupun sedang mencari service web hosting terbaik di Indonesia wajib baca artikel ini.
Mampir juga situs saya ya, banyak ulasan menarik yg bisa jadi berguna bagi para
pencari layanan web hosting murah.
Wass.

Ulasan bermanfaat tentang hosting ini sangat bermanfaat.
Bagus sekali dan bermanfaat. Tiap orang yang pakai maupun sedang cari jasa web hosting
terbaik di Indonesia wajib baca ulasan ini. Mampir juga website saya ya,
ada artikel menarik yang bisa jadi bermanfaat bagi para
pemakai jasa web hosting. Tq.

my website web hosting murah

Ulasan bermanfaat tentang web hosting murah ini keren banget.
Bagus banget dan penting diketahui. Setiap orang yang pakai maupun sedang mencari layanan web
hosting terbaik di Indonesia harus baca ulasan ini.
Kunjungi juga website saya ya, ada tulisan menarik yang
bisa jadi bermanfaat buat para pencari service hosting. Thanks.

Bagus bingitz bro, makasih ilmunya. Ini ulasan yang saya searching
sejak lama. Informasi soal hosting yang sangat berguna.
Sekedar usul buat juga sist review soal hosting murah dan olshop.
Ane mau tahu banget tentang itu.

it was nice to read to read d blog.. i wil also share it with my frnds, meanwhile go through my blog which is about printable calender, http://www.printablecalendardownload.net/ also another blog, go through this http://www.printablecalendardownload.net/
thank you

I know this website presents quality depending content and extra stuff, is
there any other web site which presents these kinds of things in quality?

Feel free to surf to my web site

Golden Globe Awards 2016 Live Stream || @ On January 10, 2016 set the date for the 73rd Annual Golden Globe Awards by The Hollywood Foreign Press.

Golden Globe Awards 2016 Live Stream
http://goldenglobeawards2016livestream.com/

Justin Bieber Tickets Tours & Concert Updates
http://justinbieberconcert.co/

Knock! Knock! Knock!!! Hello……!!!! We are back with a big bang award show which is Golden Globe Award 2016. Great show, some great people, beautiful and spectacularly talented actresses/actors and lots of fun, entertainment, and suspense’re to be revealed.

This award has been continuing since 1943. Group of writers gathered together to frame the Hollywood Foreign Press Association and made liberally distributed award named Golden globe Award where they play momentous role in film making. The first award was being honored on best achievement in 1943 filmmaking and was held in January 1944, at the 20th Century –Fox studios. Successively, every year ceremonies were held in different venues for decades.

thanks for this article....topic is good....
memberi solusi semua problem seks pasutri yang paling bagus.
solusi cepat dan tepat segala masalah seks anda.

Save them from the attack:

techiestate.com | techpepe.com/

good MSQRD for Laptop or computer, Mobile computer on Glass windows 7 Download from below. MSQRD Download Trade for exceptional trending fun photography and training video, MSQRD App Android nice.

good When we wish to promote photographs, audios, SHAREit for PC or you can finish the transferring.I myself used SHAREit app apk better.

good I have actually been utilizing Snacks Time app for iphone imobdro.com constantly invest their spare time with enjoyment. great.

页面

添加新评论

Filtered HTML

  • 自动将网址与电子邮件地址转变为链接。
  • 允许的HTML标签:<a> <em> <strong> <cite> <blockquote> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • 自动断行和分段。

Plain text

  • 不允许HTML标记。
  • 自动将网址与电子邮件地址转变为链接。
  • 自动断行和分段。
By submitting this form, you accept the Mollom privacy policy.