Live data from Hacker News

Bluesky has been dealing with a DDoS attack for nearly a full day

theverge.com

91–100 of 107 posts

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#91

Earlier quoted context omitted.

Or they'll (the site operators using Cloudflare proxy) make ill considered firewall rules like "If not Chrome, require security check".

What's your point? You can configure this in Nginx too

Nginx has a built in recaptcha page based on rules? News to me.

Even if it does, the point of Cloudflare's WAF is to avoid the traffic touching the origin if the security check doesn't succeed, so any nginx solution isn't really providing the same value.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#92

Earlier quoted context omitted.

Bluesky has never been distributed/decentralised. It's a single central system, which fetches 0.001% of user data from external systems if the user opts in, and has a marketing team that calls this decentralisation.

The Bluesky app view is centralized in that it can decide which content to show, but A) the hosting of that content is decentralized, and B) alternate app views like Blacksky exist which are fully independent of Bluesky (both Bluesky the company and Bluesky the app view). The Bluesky app view could stop showing users content from Blacksky (or any other) PDSes, but that's it. If you're using the Blacksky app view, afa…

ATProto would need to use signing key cryptography and content addressable storage to be distributed. If we can't store our data with third parties or create an offline-first system then it's not a decentralized social network.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#93
post #92

Earlier quoted context omitted.

The Bluesky app view is centralized in that it can decide which content to show, but A) the hosting of that content is decentralized, and B) alternate app views like Blacksky exist which are fully independent of Bluesky (both Bluesky the company and Bluesky the app view). The Bluesky app view could stop showing users content from Blacksky (or any other) PDSes, but that's it. If you're using the Blacksky app view, afa…

ATProto would need to use signing key cryptography and content addressable storage to be distributed. If we can't store our data with third parties or create an offline-first system then it's not a decentralized social network.

ATproto does support storing data elsewhere. That’s what a PDS does. I’m not sure what you mean by an offline-first system in this context though or why it’s required for decentralization. Could you elaborate?

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#94

Earlier quoted context omitted.

At least Apple devices are actually secure and can't really be omitted from things other than gaming and business. Granted, gaming and business are pretty important.

You mean except for that 0day exploit kit floating around on github last week right?

[dead]

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#95

Earlier quoted context omitted.

A week or two ago, when there was a Bluesky outage and a Claude outage at the same time, people were earnestly pointing to that as evidence that Claude was somehow a load-bearing component of Bluesky, or that AI vibecoding had caused the outage... I had to just disengage but I was also very annoyed by it all.

people really do struggle to differentiate between correlation and causation. we humans love our patterns so that we can make sense of existence.

More like a struggle to STFU about things people don't know much about. I don't think the comments are thought out at all beyond being said in reaction, or likely to get a reaction.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#96

Earlier quoted context omitted.

You mean the iOS version people are refusing to upgrade from because of the shittified forced UI changes?

You aware that iOS 18 is patched right and "old" means 17 and before?

AFAIK Apple released a patch for EOL devices and not devices which are supported by v26.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#97

Earlier quoted context omitted.

You aware that iOS 18 is patched right and "old" means 17 and before?

AFAIK Apple released a patch for EOL devices and not devices which are supported by v26.

False, just updated one a day or two ago, it keeps suggesting iOS 26 but below that was 18.7.7

the amount of people not updating anyway is less than .1%

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#98
post #67
post #16

Earlier quoted context omitted.

Truth is if mastodon.social gets ddosd the same as Bluesky I can still use the rest of the network fine. Proof is in the pudding. tons of instances that make up the fabric of redundancy. I think most people would be served better if Bluesky acted differently early with their rollout in a sharded manner?

This is half true. If mastodon.social goes down every single one of the accounts made on that instance go down as well. In truly decentralized protocols you own your identity and can take it elsewhere, for instance, in Nostr and SSB, a relay/pub going down is no big deal since you can connect to other servers and maintain communications.

historic posts from the known network and (sometimes media, instance setting) are cached on your own instance in ActivityPub. interactions travel across the known network graph. if an instance vanished forever, overnight, there is at least an imprint of it across the network, albeit instance specific. that may be by design, there are jurisdictions that have people complying with laws and things. not sure how the ecosystems you mention deal with that in particular

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#99
post #98
post #67

Earlier quoted context omitted.

This is half true. If mastodon.social goes down every single one of the accounts made on that instance go down as well. In truly decentralized protocols you own your identity and can take it elsewhere, for instance, in Nostr and SSB, a relay/pub going down is no big deal since you can connect to other servers and maintain communications.

historic posts from the known network and (sometimes media, instance setting) are cached on your own instance in ActivityPub. interactions travel across the known network graph. if an instance vanished forever, overnight, there is at least an imprint of it across the network, albeit instance specific. that may be by design, there are jurisdictions that have people complying with laws and things. not sure how the ecos…

That doesn’t answer the point I’m making. If the instance your account was made on explodes, YOU lose your social graph, wether some of your posts survive cached elsewhere is not relevant, your account is gone, and so are your connections.

You have no way to prove an account made after the original instance went down belongs to someone, that’s the issue with federated systems.

As for content moderation, in nostr relay operators such as nostr.build handle legal takedowns on a daily basis, SSB is a little trickier since it’s mostly p2p but pubs are still able to control what flows through them to some degree.

Re: Bluesky has been dealing with a DDoS attack for nearly a full day

#100
post #49

Earlier quoted context omitted.

> Even when Bluesky confirmed it's a DDoS, the line is now "maybe they wouldn't have gotten DDoSed if they didn't vibecode and their code was better." The context of the "jokes", regardless of if one finds them funny, is that this is exactly how AI boosters (including the bluesky team) have been behaving. Every little benefit, no matter how small or unfounded, was being attributed to AI usage. So people do the opposi…

As I understand things, the only AI tool the Bluesky team has been pushing has been a feed generator/curator. They have been pushing for vibe coding their systems or for using AI to generate content on Bluesky.

Have not*
Post reply on HN