Given that bluesky was hit a few days ago, could be a threat actor gauging the defenses/responses of 2nd tier targets. I wouldn't put it past musk to use ddos to generate bad press for non-x socials either.
Plenty of ways this could be worth someone's resources even if complete take down isn't on the table.
They can, but usually don’t. I’ve heard of systems being vulnerable to attack when resource usage is completely maximized. They can definitely cover up an intrusion or test a botnet, though, and I suspect this was a botnet test. Mastodon users overwhelmingly strike me as not worth unmasking. (And that’s a good thing)
Depends on their goal. They still inconvenienced a significant amount of people on Mastodon, especially since the flagship instance has a lot of users. Of course if this causes users to spread out to other instances, then I guess that's a net good thing and can be attributed to fediverse resiliency.
Sure but it is ultimately futile because Mastodon, using the ActivityPub protocol, aka The Fediverse, can't be completely shut down. Somebody ddos's one instance, well there are other instances you can join to easily defeat the ddos.
You make a good point, however a counterpoint: Instance information is not hidden. It would be relatively trivial for a bad actor with resources to DDOS one instance to add other instances.
21 Comments
The_Picard_Maneuver@lemmy.world · 65 pts · 145d
At least Mastodon is properly federated. The benefits of decentralization sort of make this a waste of money/resources, right?
I remember when this was happening to Lemmy all the time too.
tofu@lemmy.nocturnal.garden · 37 pts · 145d
Depends on what your goal is. .social has half a million active users every month, so it certainly had some impact
Foni@piefed.zip · 9 pts · 145d
What fraction of the total users is that?
rainwall@piefed.social · 13 pts · 145d
About 30% looks like.
JupiterRowland@sh.itjust.works · 1 pts · 140d
Some 22% of the entire Fediverse (except Threads).
Hegar@fedia.io · 35 pts · 145d
Given that bluesky was hit a few days ago, could be a threat actor gauging the defenses/responses of 2nd tier targets. I wouldn't put it past musk to use ddos to generate bad press for non-x socials either.
Plenty of ways this could be worth someone's resources even if complete take down isn't on the table.
Sl00k@programming.dev · 7 pts · 145d
This actually ended up not being an external DDOS. They shipped some code that ended up hammering their servers.
JupiterRowland@sh.itjust.works · 1 pts · 140d
Old and busted: Mastodon DDoSes the non-Mastodon Fediverse due to design decisions.
New hotness: Mastodon DDoSes itself due to design decisions.
jafra@slrpnk.net · 35 pts · 145d
How long will it take for them to learn the fediverse is resilient?
Gullible@sh.itjust.works · 19 pts · 145d
For all we know, they achieved their goal, irrespective of .social’s uptime.
jafra@slrpnk.net · 6 pts · 145d
Do ddos open up the server? My naive understanding is it only hinders its reachability?
Gullible@sh.itjust.works · 6 pts · 145d
They can, but usually don’t. I’ve heard of systems being vulnerable to attack when resource usage is completely maximized. They can definitely cover up an intrusion or test a botnet, though, and I suspect this was a botnet test. Mastodon users overwhelmingly strike me as not worth unmasking. (And that’s a good thing)
scytale@piefed.zip · 12 pts · 145d
Depends on their goal. They still inconvenienced a significant amount of people on Mastodon, especially since the flagship instance has a lot of users. Of course if this causes users to spread out to other instances, then I guess that's a net good thing and can be attributed to fediverse resiliency.
tofu@lemmy.nocturnal.garden · 6 pts · 145d
Who do you mean with them?
Goodlucksil@lemmy.dbzer0.com · 5 pts · 145d
The DDoS perpetrators
tofu@lemmy.nocturnal.garden · 11 pts · 145d
Well they targeted the biggest instance. Their attack didn't stop mastodon as a whole, but many users were impacted
jafra@slrpnk.net · 2 pts · 145d
Maybe it was about silencing s/o on this instance for some time. Idk.
FreeBooteR69@lemmy.ca · 3 pts · 145d
Sure but it is ultimately futile because Mastodon, using the ActivityPub protocol, aka The Fediverse, can't be completely shut down. Somebody ddos's one instance, well there are other instances you can join to easily defeat the ddos.
daychilde@lemmy.world · 3 pts · 145d
You make a good point, however a counterpoint: Instance information is not hidden. It would be relatively trivial for a bad actor with resources to DDOS one instance to add other instances.
SharkAttak@kbin.melroy.org · 3 pts · 145d
them' mofuckers.
onlinepersona@programming.dev · 13 pts · 145d
We need more DDOS attacks on Xitter. Wouldn't it be great if Xitter became so unstable people willingly left?