Intermittent Outages Due to DDoS

in #steemit5 years ago

Steemit.com has been subjected to a sustained DDoS attack that brought down the website for roughly 25 minutes earlier today. The Steemit Team is working to mitigate the attack, but steemit.com is still experiencing intermittent outages.

Condenser Split?


The outages are unrelated to any recent changes that were applied to steemit.com. The DDoS attack only affected the steemit.com website. The blockchain was unaffected, and other websites that interact with the blockchain have remained operational during the attack.

We will do our best to keep you informed as the situation unfolds.

The Steemit Team

Sort:  

gives you guys legitimacy

I was surprised it took so many years for this to happen.

this is about the fourth time it's happened.

That sounds about right.. I thought this was the first. Anyways, im using enough Dapps to post stuff on Steem that it never really mattered to me.

It has happened several times in the past.

No wonder.. i thought this was the first

The previous attacks were a long time ago. Here's a post about it if anyone's still interested.

Thanks for the links! I think i missed the announcement back then.

I tried to warn you about those damn Russian bots!!! This would not have happened if I had been elected. This is what happens when you put bad orange man in charge.

Hey, @steemitblog.

Thanks for the heads up. It really is appreciated and nice to know when it's just something on my end acting up, or part of a larger issue.

It's still been a little temperamental this morning, so I'm wondering if the intermittency is still ongoing as of now? Going to try to see what I can do through Steemit this morning, since it always seems to be the front end I end up using. :)

Haha, good to know. Yes, I think it's interesting that despite the many new interfaces, steemit remains the most used interface by far. While we're definitely putting a lot of thought right now into how we're going to make steemit.com better, I think it's still important to ask ourselves what it was about steemit.com that made it so compelling early on (certainly wasn't the UI) and why people still use it at all, despite the low retention rates. We certainly want to make it much better, and fast, but I think we also don't want to destroy the magic. Thoughts?

Yeah, I've been experiencing intermittent outages as well. We're still working on it and we'll provide an update as soon as we have new information.

Hey, @andrarchy.

Okay on the ongoing outages.

re: thoughts

Well, if we're looking at what not to take away, I would say that would be to keep the clean look—simple, intuitive, unencumbered feel. Keep the fonts and the font sizes. The more fancy things get, the feel of a site tends to get cluttered. Keep it fast. Keep it lean and mean. I guess the formatting can change to some degree, the fact that it loads blink of the eye in the browser and that there's not much if any lag are all strong points. Mostly, I'm just trying get in and work, anyway.

In fact, the only two things I've wanted really from the beginning was the ability to save multiple drafts, and to schedule posts. Having an option to see my feed differently, or different colors, or what have you, that might be fun, but it's not part of the core user experience in my opinion. :)

I actually like steemit.com's UI. I don't really like large graphic images taking up too much space because scrolling becomes tedious fairly quickly. I would be careful about any changes you make. I remember I used to use Yahoo Sports for years and years and then one day they redesigned it just for the sake of change and it was awful. I switched to ESPN's website and I've never gone back to Yahoo Sports since.

Yahoo Sports has changed the design back to the simpler way it was before but by then it was too late as I had gotten used to ESPN.

Thanks for the heads up.

We always have our head up here at steemit. Little known fact, the head is the best part of your body.

It's still been a little temperamental this morning

We call that a bad hair day in the biz.

Back making the rounds I see, @nedshair. :)

@steemitblog,
These basters should understand they can't win by DDOS on STEEMIT and it might not affect on STEEM as well!

Cheers~

I don't know how much the nodes could handle an attack... I imagine any number of attacks there could render a large majority of the platform basically null and void.. the vectors of attack could be even as simple as spamming tens of thousands of both legitimate posts and illegitimate posts in the form of bad keys, transactions over limts, invalid json and/or otherwise.. be careful of name-calling I guess is the short of it. I don't know what safeguards are in place. Are there tools in place to handle the pressure in the form of processor, ram, bandwidth and disk space attacks.... ? I'm not a full dev, so I can't look into all these inner workings myself. But since a ddos is on the radar, food for thought. See you all on the flip side of this attack, we got this!!
@ned @steemit @steem

Posted using Partiko Android

Are there tools in place to handle the pressure in the form of processor, ram, bandwidth and disk space attacks.... ?

At UI level we have same issues and solutions as any other web application on the Internet.
At the blockchain level we have Resource Credits system:

The RC Plugin defines blockchain resources and limits medium and long term use through stake based Resource Credits. Based on the usage of a particular resource, there will be a market price in RCs. When a transaction is included, the issuing account will be charged a number of RCs according to the resources consumed by the transaction.

Thanks to solid decisions made by innovative developers, the witness core, Steem is getting more and more decentralized as time goes on. Coming more and more in the future will be applications that enable rpc selection and even fail overs . Thus less down time overall, As well as the constant battle testing (like the negative vest and bigga dicka attacks) we really do have a solid chain right now. It takes a village to make steem work, from developers to end users and promotors .

Thanks for the simple, frank and respectable explanation. That's why you've got my vote for witness. (Not fishing for an upvote). Ps.

At one time, I seem to remember being able to deny payout on a comment. Do you know of an easy way for a user to do that?

Posted using Partiko Android

Thank you.

Ability to declining payout depends on the frontend you are using, I have no idea how or if that can be done in Partiko, but on a Steemit site you can set in your preferences.
That would however work only for comments created by that site.

Cool. I never knew about that. It looks like it all or nothing though, which is fine because I could change it then change it back. But it's good to know there is a way to do it. Thanks.

Posted using Partiko Android

Funny right after the Tweets to the Senators about our platform we get attacked the next day. Shady ass big tech companies behind it I bet.

Posted using Partiko iOS

Thank you for information @steemitblog

Posted using Partiko Android

It would be nice if we got more updates on stuff like this when it's happening. Steem isn't a normal platform...and people don't really like how closed normal platforms are anyway. It would be nice to hear/see normal updates on things happening, when you're adding new servers, when you're receiving attacks, when you get new employees, when they have birthdays, etc, etc, etc. You need to be the friendly neighborhood Steemians, not Ozcorp.

We're not Ozcorp! ;) We've been trying hard to improve our communications which is why we've been putting out engineering updates every week. One challenge for us is that we have a lot of security concerns and many Steemit employees are extremely security conscious, and for good reason. Their obsession with security is what helps keep our users and our app developers safe. But we do have projects in the works specifically aimed at giving better insight into the organization. But we also have more work than time and time spent not engineering is time spent ... not engineering. Thanks for the feedback!

Yeah, many of us on here have all sorts of security concerns. We have a ton of users here that are anonymous, despite the efforts by some to pressure everyone to doxing themselves. They shouldn't ignore their security concerns. That's actually what killed Google+ when they tried to launch and just fell flat on their face because they ignored the concerns of their users and employees who didn't want another Facebook.

Of course it went on for quite some time on life support. Too bad they didn't just take out the huge shiv they shoved into it and patch the bleeding artery.

I have of course noticed the efforts to try to improve communication. But I've also seen many companies try to over the years...and often it stops after a short time. Unless they manage to overcome the hump and fundamentally change the way they interact with the public. Steemit Inc has been cut off from all of Steem for some reason. It's good seeing this starting to change...but...it's not going to be easy. Good luck.

Http was never meant to be a final soltuion. Get the esteem application and check out the full node reports to get rpc . Or deploy your own rpc ( we are )

I'll just use a different front end for now. Hope this is resolved soon

Posted using Partiko Android

So that's why I've been getting so many gateway error messages today.

I'm using steempeak and haven't had any issues at all, the beauty of Steem, one frontend doesn't work move to another.

Crazy to think we are so under the radar, people still think steemit is steem

Yeah, it can't last forever though. I just hope the blockchain can scale when the masses arrive. With Mira, it looks like it will be ready for the most part.

The blockchain can handle it, steemit is just one app on the steem blockchain... steemit not working? No problem use another platform #cantstopsteem

Well, this reminds me of two important things for steemians:

  • use Discord. Go on one of the steem-related servers there for information if you have steem-related problems problems ;)
  • use another frontend. Perhaps the problem is not with the blockchain but with the frontend...

And another thing: Steem > Steemit :)

Posted using Partiko Android

Oddly, Facebook also was experiencing difficulties too.

Would be awesome to read some postmortem by the Steemit.inc team once the dust settles.

Also would be cool if someone would take responsibility for this DDOS. Anyways, as @ssjasasha said, it gives Steemit.com legitimacy.

Thanks for the prompt update.

I knew something was up.

Muy bueno mantenernos informados sobre los avances y la correcciòn de los ataque a la web de steemit, que afortunadamente no ha causado daños a la cadena de bloques.

It would be funny if the traffic got high again from Google and we thought it's a DDoS attack. Stop Refreshing guys!

A twitter attack! lololol

Hehe, that would be cool. It reminds me of the famous "Reddit hug of death" where small websites that get linked to on the frontpage goes offline because it can't handle the traffic it gets.

I doubt that this is what is happening with Steemit though. It seems more likely that some "hacker" group is just fucking around.

Probably the EOS folk trying to keep us down....

Posted using Partiko Android

Bernie and FTG?

Posted using Partiko Android

@partico has been working great as well !!

Posted using Partiko iOS

I see it positive. Being attacked is a sign of being important to the attacker to attack in the first place. Ok, well, not always and in any case. Yes, I was wondering too, why the steemit frontend is not loading properly.

Not necessarily. Script kiddies are just doing it randomly for fun. They don't profit from it even.

Fascinating. Who would DDoS steemit.com?

Posted using Partiko Android

Thanks for the prompt update 🙏🙏🙏

Thank you for the update.

Posted using Partiko Android

Hopefully nobody figures out how to DDOS a blockchain XD

Posted using Partiko Android

Thanks for the info

Posted using Partiko iOS

Thanks for the information.

thanks for recovering efforts ! :) 💙 ♩♬

Posted using Partiko Android