Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes but they don't explain what the mitigation is.


During an ongoing attack? I wonder why not...


Right. Not looking for specifics. My curiosity would be satisfied by something like "we've reached out to Baidu and they've done X and Y. Meanwhile, traffic has decreased so we've unblocked the affected repos."

Just a bit more transparency on the situation.


It's not baidu.com that serves that malicious code, it gets inserted on its way through the Great Fire Wall.


They might release a post-mortem once it's over, but I wouldn't expect any transparency during the attack itself.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: