Live data from Hacker News

Bluesky has been dealing with a DDoS attack for nearly a full day

theverge.com

31–40 of 107 posts

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#32
post #16

Earlier quoted context omitted.

Truth is if mastodon.social gets ddosd the same as Bluesky I can still use the rest of the network fine. Proof is in the pudding. tons of instances that make up the fabric of redundancy. I think most people would be served better if Bluesky acted differently early with their rollout in a sharded manner?

True. The only 'distributed' part of bluesky is in the PR. Otherwise there'd be more instances. My mastodon account is not even on mastodon.social, because why would I, when I could have a home server closer to home

i get real tired of people trumpeting that bsky is distributed.

Can i run a private node? can i run a functional node completely within my network segment? because i can with gnusocial and misskey; i've never run mastodon; i am on fosstodon and a couple of other mastodon-likes.

bluesky is to discord what mastodon (fedi) is to IRC.

don't let the fact that most people use the main instances fool you, there's thousands (maybe tens of thousands) of instances. I haven't seen a tally recently, i forget the account that shows them for each "instance type", like pleroma, misskey, mastodon, pixelfed, whatever the reddit clone is, whatever the 4chan clone is, and so on.

anyhow when elon bought twitter mastodon surged. I hope they didn't spend millions upgrading the main instances because most of that dropped off because, you know, everyone's on twitter. only a few million on mastodon.

My whole point is, trying to shoehorn words like "distributed" into a system that i cannot run independently is, well it's just not distributed, that's all.

edit: maybe this is sour grapes because i never got an invite; but maybe i think it's just twitter with a different coat of paint and different buzzwords attached.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#33

The prevalent discourse/attempt-at-a-meme-but-people-are-taking-it-seriously saying "Bluesky is down because of AI vibecoding!" is starting to get annoying and unoriginal. Even when Bluesky confirmed it's a DDoS, the line is now "maybe they wouldn't have gotten DDoSed if they didn't vibecode and their code was better."

Theoretically, if the backend code is optimized enough, a DDoS attempt wouldn't lead to a denial of service since all those requests would just get served as normal. And as long as the network isn't the bottleneck, which it probably is in most cases.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#35

Is this just for fun or is there some underlying purpose to those type of attack? Is it possible to have any certainty when answering that question?

Depending on size, such attacks can be very costly to organize, at least in opportunity cost (that is, using a botnet to attack BlueSky doesn't cost anything per se, but it does mean you can't use it for some other purpose, such as attacking someone else or mining Bitcoin).

If you're asking in general, DDoS attacks can absolutely serve a purpose - either to punish an organization that the attackers are unhappy with, or to hide some other more targeted attacks in a flood of errors, weird behaviors, and tired sysadmins.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#37

The prevalent discourse/attempt-at-a-meme-but-people-are-taking-it-seriously saying "Bluesky is down because of AI vibecoding!" is starting to get annoying and unoriginal. Even when Bluesky confirmed it's a DDoS, the line is now "maybe they wouldn't have gotten DDoSed if they didn't vibecode and their code was better."

Would be funny if this nonsense came mostly from bots to distract from the fact that Bluesky isn't decentralized and thus easier to take out.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#38

The interface seemed to function as normal, but specifically the API was targeted, which left a lot of confused users who were seeing the interface peppered with errors. Watching as it unfolded, it seems it affected certain regions to begin with and then slowly spread worldwide. Seems they might have failed to host the status page ( https://status.bsky.app ) separately as well, because that went down several times th…

The status page seems hosted by UptimeRobot, so it looks like it was a problem on their end.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#39

Earlier quoted context omitted.

At least Apple devices are actually secure and can't really be omitted from things other than gaming and business. Granted, gaming and business are pretty important.

You mean except for that 0day exploit kit floating around on github last week right?

You mean the one for old ios versions?
Post reply on HN