Today, like the past few days, we have had some downtime. Apparently some script kids are enjoying themselves by targeting our server (and others). Sorry for the inconvenience.

Most of these 'attacks' are targeted at the database, but some are more ddos-like and can be mitigated by using a CDN. Some other Lemmy servers are using Cloudflare, so we know that works. Therefore we have chosen Cloudflare as CDN / DDOS protection platform for now. We will look into other options, but we needed something to be implemented asap.

For the other attacks, we are using them to investigate and implement measures like rate limiting etc.

top 50 comments

sorted by: hot top controversial new old
[–] 381 points 3 years ago (92 children)

Thank you for the amazing job, as always! Cloudflare is a solid solution :)

  • source
  • hideshow 92 child comments
  • load more comments (92 replies)
    [–] 206 points 3 years ago (6 children)

    Don't forget. Donate to them. There are no ads here. So we have to maintain the staff and servers.

    Lemmy World

    https://www.patreon.com/mastodonworld?utm_campaign=creatorshare_fan

    Lemmy Devs

    https://www.patreon.com/dessalines?utm_campaign=creatorshare_fan

  • source
  • hideshow 6 child comments
  • load more comments (6 replies)
    [–] 173 points 3 years ago* (13 children)

    Imagine hosting a service for anyone else to use it, free of charge, no ads, free & open API, yet some idiots think it's fair to (D)DOS it.

    There are more "interesting" targets, worst case - Reddit, who thinks everyone is just a number/noise.

    Just leave Lemmy alone. :(

  • source
  • hideshow 14 child comments
  • load more comments (12 replies)
    [–] 119 points 3 years ago (21 children)

    I don't understand why people want to take down websites. Especially sites like Lemmy, which isn't exactly sticking it to anyone because no one owns it!

    Are they just Reddit groupies?

  • source
  • hideshow 23 child comments
  • [–] 147 points 3 years ago (2 children)

    For most hackers or wanna-bes (often called Script Kiddies, that is, people (generally young, even children thus the "Kiddies") who are not technologically inclined enough to be real hackers and see a tutorial online on how to run pre-written scripts that repeatedly perform various functions), the answer to "Why do you do it?" is often:

    1. "Because I was bored."

    2. "Because I can."

    Very rarely are other reasons given.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (2 replies)
  • [–] 30 points 3 years ago

    Some people enjoy causing suffering to others. On the internet they are termed trolls. Irl people usually just call them assholes. Most people have encountered them before.

    I think they are far more common and likely than anyone giving two shits about reddit.

  • source
  • parent
  • load more comments (19 replies)
    [–] 92 points 3 years ago (2 children)

    In case you haven't considered this, some helpful advice. To keep them from the lemmy.world door after the CDN installation

    • Change the public IP addresses
    • rotate your certificates
    • block all traffic appart from the CDN and only allow a limited known good IP addresses (like yours and your support team). These steps will make your server harder to find, hopefully they move on.
  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 90 points 3 years ago (2 children)

    Good News

    Most of these β€˜attacks’ are targeted at the database

    A major PostgreSQL performance issue, logic mistake, was discovered today in lemmy_server and is an easy fix. Details: https://lemmy.world/post/2008987

  • source
  • hideshow 3 child comments
  • load more comments (1 reply)
    [–] 81 points 3 years ago

    Growing pains. This server and the platform will be better for it. If not for these script kids, some other attacker would eventually be motivated to try it.

  • source
  • [–] 60 points 3 years ago (1 child)

    old.lemmy.world still exposes your hetzner server to the internet, just a quick heads up.

  • source
  • hideshow 2 child comments
  • [–] 47 points 3 years ago

    Thank you as always for the transparency. This instance is going to be the most targeted because of its size. Y’all dealing with this is hard but you’re going to figure things out that will help the other instances.

  • source
  • [+] 44 points 3 years ago (2 children)
    load more comments (2 replies)
    [–] 40 points 3 years ago

    It's not. People hate large companies that have a dominant position in their industry. Usually, that's fair. However, in the case of DDoS protection, you have to have a large overbearing presence to be able to have the capacity to withstand such attacks. People don't know how to see through what's typically true for what's true in this case. Do I like having a dominant player in an industry? Not particularly. Do I understand why it's necessary in this case? Yes.

  • source
  • [–] 39 points 3 years ago (2 children)

    Anything we can do as "users" to help, other than donating?

  • source
  • hideshow 3 child comments
  • load more comments (1 reply)
    [–] 33 points 3 years ago (13 children)

    Excellent! CDN and DDoS protection are essential. Also would recommend looking into load balancing if you haven’t.

  • source
  • hideshow 13 child comments
  • load more comments (13 replies)
    [–] 33 points 3 years ago (4 children)

    Come on everyone, let's be better than this. Ruud literally said script kids, why do yall have to go and blame reddit? The Lemmy gets more attention, and chaotic dumbasses do their thing. You don't have to do any mental gymnastics to tie it back to spez.

  • source
  • hideshow 4 child comments
  • load more comments (4 replies)
    [–] 32 points 3 years ago* (last edited 3 years ago) (1 child)

    That's for for always keeping everyone up date. Sucks that you have these people wanting to DDOS a free community of people, I don't get it.

    Either way thank you. Now to just somehow find a decentralized version of CloudFlare so we don't have to deal with there trackers that they have.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 32 points 3 years ago

    Thank you for your hard work, and for keeping us updated on the situation.

  • source
  • [–] 30 points 3 years ago (10 children)

    Wonder why this wasn't done earlier. Hopefully we'll see less of the 404-type pages that has plagued this instance.

  • source
  • hideshow 10 child comments
  • load more comments (10 replies)
    [–] 30 points 3 years ago (1 child)

    Thank you! I will donate tomorrow

  • source
  • hideshow 2 child comments
  • [–] 29 points 3 years ago (1 child)

    Cloudflare isn’t bad per se, but having huge amounts of the public internet behind a centralized provider is bad for the flexibility and resiliency of the internet as a whole.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 27 points 3 years ago

    On the plus side watching you all tackle and solve these problems gives me confidence in the long term viability of Lemmy and the fediverse. The transparency and often detailed technical discussion definitely helps a lot too.

  • source
  • [–] 27 points 3 years ago (1 child)

    Man I would love to know how/why doing that is enjoyable to some people. Like how sad and pathetic is your life that that is what is fun to you?

  • source
  • hideshow 2 child comments
  • [–] 24 points 3 years ago

    Cloudflare is a solid choice IMO. Thanks again for hosting this!

  • source
  • [–] 23 points 3 years ago

    You’re doing a great job so far. Thanks for the update.

  • source
  • load more comments
    view more: next β€Ί