Live data from Hacker News

Bluesky has been dealing with a DDoS attack for nearly a full day

theverge.com

71–80 of 107 posts

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#71
post #16

Earlier quoted context omitted.

Truth is if mastodon.social gets ddosd the same as Bluesky I can still use the rest of the network fine. Proof is in the pudding. tons of instances that make up the fabric of redundancy. I think most people would be served better if Bluesky acted differently early with their rollout in a sharded manner?

Blacksky and other instances of bluesky are not affected, what are you talking about?

Not true, they were down because they still use bluesky's relay

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#72
post #31

I thought it was distributed/decentralised?

My understanding is that ATProto itself is definitely decentralized but the app view most people interact with using the Bluesky app is centralized ...sort of. The Bluesky app view will read from PDSes hosted by other people, hence people on Bluesky can see stuff posted elsewhere, like users of Blacksky. If the Bluesky app view decides to stop reading from any other PDS (like those of Blacksky, or ones which are self-hosted) they're free to do so. The same is true for alternative app views like Blacksky. Since most people think of Bluesky as the thing you see on the official Bluesky app (which shows the Bluesky app view) an outage of the Bluesky app view will mean they lose the ability to view any posts from any source. If someone's using a separate app view like Blacksky, the most that will happen to them should be that they'll lose interaction with posts coming from Bluesky's PDSes until the outage ends.

I may have the division between Bluesky and Blacksky off, but ATProto does allow this sort of thing. Hosting a PDS is trivial and requires very few resources. Hosting a full app view can be expensive depending on how many PDSes you're ingesting from, but you can decide how much of that you want to do.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#73
post #34

Earlier quoted context omitted.

Thought so too. Odd.

Bluesky has never been distributed/decentralised. It's a single central system, which fetches 0.001% of user data from external systems if the user opts in, and has a marketing team that calls this decentralisation.

The Bluesky app view is centralized in that it can decide which content to show, but A) the hosting of that content is decentralized, and B) alternate app views like Blacksky exist which are fully independent of Bluesky (both Bluesky the company and Bluesky the app view). The Bluesky app view could stop showing users content from Blacksky (or any other) PDSes, but that's it. If you're using the Blacksky app view, afaik Bluesky the company can't do anything other than cut you off from Bluesky's PDSes.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#75
post #74
post #31

I thought it was distributed/decentralised?

Yes, and other hosts are working normally.

I'm pretty sure the only one that stayed up at all was Red Dwarf, the rest all rely on at least some part of the "main" instance and weren't up

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#76

Hopefully there will be some post-mortem. It seems like we're don't really see that many deliberate DDoS attack anymore. Not that it doesn't happen, but they really don't provide that much value against a target like Bluesky (unless you really hate them). I'd be interested in how the attack manifests. Is it an actual DDoS? Is it highly aggressive scraping? We should be able to see this in how the attack manifests its…

> It seems like we're don't really see that many deliberate DDoS attack anymore.

There are more now then there ever have been in number of infected hosts and total data volume.

The internet is a big place.

”On 13 April 2026, 21 countries joined forces in a coordinated action week that focused on enforcement and prevention measures against over 75 000 criminal users engaging in distributed denial-of-service (DDoS)-for-hire services. With over 75 000 warning emails and letters being sent to identified criminal users and 4 arrests, the action week also led to the takedown of 53 domains and the issuing of 25 search warrants.”

Source: https://www.europol.europa.eu/media-press/newsroom/news/euro...

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#77
post #59

Earlier quoted context omitted.

[flagged]

Why would anyone blindly criticize AI tools, when there are so many flaws to see?

This isn’t surprising at all. It reminds me of staunch Apple haters who recycle superficial talking points as opposed to Apple nerds who have long lists of very pointed critiques.

What annoys me the most bsky AI hate is the assumption that people who spend a lot of time working with LLMs don’t understand their weaknesses, as if we aren’t constructing systems and evaluations to determine precisely how much AI sucks for our given task.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#78
post #8

Earlier quoted context omitted.

You’re saying a mastodon instance can’t vet DDosed?

The people I follow on mastodon come from a wide variety of instances. While mastodon.social is the largest instance, most of the accounts I follow are elsewhere. Granted, all the smaller instances are likely easier to DOS as they are small instances. But mastodon is actually decentralized. If any one instance goes down, everything else keeps working. Unlike Bluesky and ATProto which is more of a theoretical “could b…

https://arewedecentralizedyet.online/ is a fun dashboard visualizing how decentralized the Fediverse/Atmosphere is/isn't.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#79
It seems like DDoS's are getting harder and harder to deal with. The tips that worked 10 years ago are now easily worked around. I keep seeing people on here say "just use TLS fingerprinting" like it's a panacea, but I can't remember the last time an attack didn't spoof their fingerprint.

It feels like, outside of custom behavior tracking, there's no good way to truly protect your site without making it more restrictive in general. Require JS, client side challenges, cloudflare.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#80

Earlier quoted context omitted.

Bluesky has never been distributed/decentralised. It's a single central system, which fetches 0.001% of user data from external systems if the user opts in, and has a marketing team that calls this decentralisation.

The Bluesky app view is centralized in that it can decide which content to show, but A) the hosting of that content is decentralized, and B) alternate app views like Blacksky exist which are fully independent of Bluesky (both Bluesky the company and Bluesky the app view). The Bluesky app view could stop showing users content from Blacksky (or any other) PDSes, but that's it. If you're using the Blacksky app view, afa…

If by "decentralised" you mean "0.001% of it is not only hosted centrally"

They have designed a protocol that could theoretically be decentralised. Then reality hit, and it was centralised.

Post reply on HN