Bonum Certa Men Certa

Mystery Attack on SourceHut, a Leading Free/Libre Alternative to GitHub and Gitlab

posted by Roy Schestowitz on Jan 20, 2024

Months ago: (they must be losing their panties)

Microsoft's GitHub Layoffs Hitting Hundreds of Workers, All Offices Closing

THIS post is partly speculative. The conclusions, if any, are left to the readers' collective intuition.

Almost a week ago we wondered aloud in IRC; who would attack SourceHut and why? What for? We could not point the finger at anybody, as there was a lack of hard evidence. The same goes for Codeberg (overlapping code/projects).

So let's consider some context.

Microsoft's GitHub - and also Gitlab - have financial issues. Their bloatware, which sometimes they offer free of charge (not free as in freedom), requires people with high salaries to build and maintain. They also need lawyers. So we're looking at millions of dollars a year just for bare basics. It moreover requires people to babysit 24/7 and there are electricity (or hosting) bills. This does not scale well and does not look pretty. Business models are elusive here.

Who stands to benefit from the "unprecedented 170 hour outage" of SourceHut? Here is what they've just said (more links here - may be updated over time) in their official site: "We never received any kind of ransom note or other communication from the attacker. We do not know who was behind the attack, nor their motivations, and likely never will. We know that they targeted SourceHut specifically, and that they followed us as we worked on mitigations, directing their attack at new infrastructure as it was being set up."

There's a graph too:

SourceHut: We never received any kind of ransom note or other communication from the attacker. We do not know who was behind the attack, nor their motivations, and likely never will. We know that they targeted SourceHut specifically, and that they followed us as we worked on mitigations, directing their attack at new infrastructure as it was being set up.

Who stands to benefit (cui bono)? That might say something about the motivations. DDoS attacks that are potent and persistent are not cheap to launch. If there's no direct financial benefit, then what is it? Who is it?

This brings back old memories (15 years ago). This put our site offline for several days back then. We never discovered who did this. After these DDoS attacks we needed to find another host - and perhaps that too was part of the attacker's plan.

Burying the truth? Boycott Novell hit by Denial of Service attack

Other Recent Techrights' Posts

Facebook's Debt Leaps to Over 51 Billion Dollars
A lot of this is a bubble, aside from the bubble the media irresponsibly dubs "AI"
3 Days Ago Over at Tux Machines...
GNU/Linux news
Most of This Month Will Deal With EPO Scandals
A timeline of sorts
Links 01/11/2025: Microsoft Distributes Malware Again, Radio Free Asia Shut Down by Dictator
Links for the day
 
Linux.com is Becoming Microsoft
They took a once-reputable site with a vast audience and turned it into a pile of trash
Microsoft Lunduke: People Pointing Out I'm a Bigot is a Badge of Honour
It's almost as if he openly admits being a troll and is proud of it
Oracle's Debt Continues Rising to All-Time Highs, The "Slop Bubble" is a Smokescreen for Larry Ellison
wishful-thinking bubble waiting to implode completely
News on the Web is Becoming Rare, Shallow, and Difficult to Find
To efficiently and rapidly find original and important news without underlying comprehension/understanding of the news (and its context) is a hard task
Slopwatch: Linux Journal, Serial Slopper, WebProNews, and More
getting back into the habit
The Cocaine Patent Office - Part III: European Patent Office Officials Cannot Claim False Identification
Corroborating with other sources is always desirable if possible. We shall do so later in this series.
Still Catching Up, Daily Links a Top Priority
Readers who have additional information about the EPO can send it along to us
Links 01/11/2025: "Americans Are Defaulting on Car Loans at an Alarming Rate" While Many Left to Starve (SNAP)
Links for the day
Gemini Links 01/11/2025: FIFO and Gemini Age Survey
Links for the day
Why Does German Media Protect the EPO From Accountability for Cocaine?
Can we trust such media to properly inform the public?
Links 01/11/2025: Microsoft Azure Goes Offline Again
Links for the day
November is Here, Anniversary Party This Coming Friday
Expect this site to return to its normal publication pace either by tomorrow or Monday
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, October 31, 2025
IRC logs for Friday, October 31, 2025
Gemini Links 01/11/2025: Synergetic Disinformation and Software Maintenance
Links for the day
IRC Proceedings: Thursday, October 30, 2025
IRC logs for Thursday, October 30, 2025
IRC Proceedings: Wednesday, October 29, 2025
IRC logs for Wednesday, October 29, 2025