Email or username:

Password:

Forgot your password?
Eugen Rochko

We've been hit by a massive DDoS attack. The site may not work as expected. We're working on mitigating the attack. Fastly are helping us. If in doubt, check status.mastodon.social for information.

139 comments
[DATA EXPUNGED]
Sean

@Gargron someone's salty that mastodon is still up

airportline

@Gargron Just in time for Twitter to shit the bed :blobcatmeltcry:

flexghost.

@Gargron Thank you for handling it, big guns

lucas :baner:

@Gargron wonder if another service has spent more resources on DDoS than maintaining their own site, seeing as this coincides with them being down…

3nzof3rrari3

@Gargron thank goodness for Eugen! what would we do without him ... the world would be a much darker place

Pffff...

@Gargron Meanwhile, the other social network DoS-ed itself...

{"errors":[{"message":"Your current API plan does not include access to this endpoint, please see developer.twitter.com/en/docs/ for more information","code":467}]}

Luigi Trapanese

@Gargron twitter is down, could it be genuine traffic?

Arie Goldshlager

@Gargron

Could it be related to the #TwitterDown incident?

Gormulus

@Gargron Might have something to do with Twitter being down and everyone and their mother trying to use Mastodon at once?

  lamp

@gormulus wtf twitter's serving json instead of html?

corujo

@Gargron same time as twitter being broken... coincidence?

Katie Lee

@Gargron Elon's got nothing better to do now that Twitter's down, presumably.

Michael

@gargron Are you sure it's DDOS?

and not quite many people coming over from the other "social" network that is down? ;D

garpu

@Gargron It looks like twitter's down. Maybe just massive influx of new people?

  Stian Øverbye

@garpu @Gargron it’s usually very easy to differentiate between legit traffic and illegitimate traffic.

  Conor

@garpu @Gargron I think if the CEO is calling it a DDoS attack then it’s not 1000 users leaving Twitter but a DDoS attack.

Maarten Schenk :mastodon:

@Gargron Nah, just everyone coming over from Twitter to complain 😀

Andy

@Gargron external links aren't working on twitter

Naomi Dierckx

@Gargron Elon having a tantrum because his precious vanity project is down?

JosephMenn

@Gargron Thanks for handling. Any guess on motive?

Son of Sandor
Stu

@Gargron I forget who, but someone noted these happen around the time Twitter has significant issues. Fancy that.

Ernie Smith
Mike Fraser :Jets: :flag:

@Gargron Site loads fine for me. Resolved?

sj_zero
Thoughts to you guys. It's sad that certain people want to take something good and destroy it for no good reason. ✊
Lee
@Gargron Those people (Twitter or Bluesky shills?) need to get a life.
morph
ꗥ🌸 KitaneaKitty 🌸ꗥ
Nagmay

@Gargron Are we sure it isn't just a massive rush from people abandoning #twitter?

  Fuck Elon :mastodon:

@nagmay @Gargron

It is certainly a weird coincidence that exactly when Twitter is down we suddenly get a DDoS attack. I wonder...🤔

  casey is remote
FirefighterGeek :masto:

@Gargron Nice that federation results in a working Mastodon experience for most not being interrupted.

In theory, I suppose, you could have a secondary account on another instance following the same people and have built in personal redundancy.

  Bowreality

@FirefighterGeek @Gargron I have a secondary account. Just in case. I update followers once a month. They are totally unrelated so that gives me access even if my instance is down.

  FirefighterGeek :masto:

@bowreality @Gargron I'd love to set that up, but I know I would never get around to keeping them in sync. Would be a cool third party plug in though.

  Bowreality

@FirefighterGeek @Gargron It’s very quick to export followers and import them on the 2nd account but I agree a tool would be nice

  Christian Pietsch 🍑
  Cedara 📖🍵🤍

@FirefighterGeek
Most of the old-time users have a secondary account, I bet.
@gargron

Mr. Thoroman

@Gargron yep. World wide culture war stuff. They fear Mastadon!

  Meow.tar.gz :verified:

@cautionarytale @Gargron They fear what they are unable to control. Since Mastodon is decentralized and not owned by any corpos, it's difficult if not impossible to contain.

  Mr. Thoroman

@ablackcatstail this is true, a huge number of intellectually gifted people gathered here per chance, in what could be a public globalization effort. This place enables alternatives for everyone with its diversity, and purpose.

Heart of a Crone (Milly)

@Gargron Do you happen to know who is doing it? Are you willing to day?

Marcelo Arias
Monique

@Gargron Gees, why do people do this stuff, seems for some so hard to leave other people's things alone.

CalamusEstFortis

@Gargron Everything working fine for me right now, so whilst it still is...

🔶 Find #JohnMastodon 🔶

He'll know what to do.

Tylor Sweeney

@Gargron thank you and the entire team for all the hard work keeping everything running as smoothly as possible.

Shawn Powers

@Gargron This sucks, truly, and yet also shows how incredible decentralized infrastructure is for a platform.

(This is an example of something I'd quote-toot, and I'm still not sure how that is "properly" done... I didn't screenshot because I know the concept is offensive to you personally. Anyway, as to the original toot, thanks for making a platform so open and resilient.)

hajota
DELETED

@Gargron Good luck to you guys in weathering the storm. ❤️ #fediverse

A goat :verified: :verified:

Looks like the DDoS attackers forgot to take down every other Mastodon instance... I didn't even know this until somebody else mentioned it.

  DELETED

@nus
mstdn.ca is unaffected. A great day for Canada, and therefore the world!

KlonAmy
Jane Kaylor
Lennart Koopmann
Raul Portales

@Gargron DDoS or sudden surge in legitimate interest by Twitter being down?

Micah

@Gargron It's no DDoS, it's everyone coming on to masto to post #twitterdown and upload screenshots of the json responses they were getting

  Jörg Seidel

@bougiekitty @Gargron Strange that they do this only at one of the many instances.

  Nemo_bis 🌈

@lostgen Actually other instances have reported higher load too.

Check the stats at mastodon.fediverse.observer/li : mastodon.social has 13 % of total users active in the last month, vs. e.g. 40 % in troet.cafe. So it stands to reason that returning users might create bigger swings in one case than in the other.

However I have no information to doubt Gargron's assessment on the source of today's downtime.

Frydee Knight

@Gargron it would explain why I had to make 2nd Account and start anew

Pusher Of Pixels

@Gargron another bene of a distributed system.

They *can't* DDos all the instances.

#Fediverse #FediStrong

Sean

@Gargron Am I the only one wondering if these attacks come from #Musk and his fascist cronies?

requiem 🏴

@Gargron This is a good reminder to federate early, federate often.

It's much harder to stage such an attack against a million tiny nodes than a single big one.

Chris ⚛️
Stefan

@Gargron best wishes for conquer this attack.😈

This #DDoS should also good reminder as well, to spread users across many #Instances and don't let them pile up at one. 😉

chuls
Ajwseven

@sportsbots This might be why you were having issues with mastodon.social.

Eric Gilmour

@Gargron Suspicious timing with the twitter outage, did someone time this attack to prevent another migration of users I wonder

GJ Groothedde 🇪🇺
Eugen Rochko

Everything is back to normal now. Yes, it was an attack, not legitimate traffic. No, we don't know who was behind it. I agree the timing with Twitter being down was unfortunate.

  andrew!

@Gargron maybe the api team at twitter got reassigned to ddos attack mastodon

  Eugen Rochko

Fastly and Datadog who both sponsor us by providing us a free service were instrumental in analyzing and mitigating the attack. Shout out to our own team as well, glad I don't have to do this alone anymore!

  stux⚡

@Gargron :ad: :catblush:

Kidding! Well done mate :cat_hug_triangle:

  Eric Redegeld💻🏎️☀️🙋💖
  sandywb14

@Gargron Thanks to all! The spirit of this community is heart warming.

  i am root

@Gargron I know the team is busy, but could you please prioritize requests for adds/changes to instances on joinmastodon.org/servers? Not waiting on anything myself, but have seen several other #MastoAdmin reporting a lack of any response. During these Twitter and mastodon.social outages, it would be very helpful to have more places for users to land.

  Alwyn Soh :sgflag:

@null @Gargron ditto on this, submitted and still waiting for a response.

  Purple :verified:

@null @Gargron Want to add I submitted a request to be added a month ago with no response.

I'm in no rush, but at the same time I've spent a fair bit of time tightening the infrastructure so it's up for the job, so it would be cool to be added :)

  Jens Ljungkvist :mastodon:

@null @Gargron

I agree!
We want it to be a Fediverse, right? Not just a few stars?

  TriciaB
  Dismal Manor Gang

@Gargron Time to start a fund drive for a Korbomite device (original Star Trek).

  HugoPoi

@Gargron This can be related to the down Ielo ISP in France
The timeline match.

  Touaregtweet
  Jeff the Alien

@Gargron Will there be a blog post detailing what and how it all happened, and list any IOCs, etc.?

  Thomas Blechschmidt
  DELETED

@Gargron
Thank you.

Phone browser works, tethered lappie gets 403...54113
Errors

Mstdn.social working on same machine.

  masyfil
  Laure
  Dan Gillmor

@LaureM Not necessarily. Depends on the circumstance. The Post could easily host its own instance. A smaller newsroom would have trouble. @Gargron

  𝕃𝕦𝕔𝕒𝕤 𝔸𝕥𝕜𝕚𝕟𝕤

@Gargron Are you not employing any sort of rate-limiting?

  beforewisdom 🖖

@timberwraith

It is a prelude to invasion. Those aliens whose UFOs we shot down.

  Esceedee
  @CharleneTeglia
  John Carlsen

@Gargron

I still see this via US-CA-SJ:

Error 403 Forbidden
Forbidden

Error 54113
Details: cache-sjc10058-SJC 1678140947 872542668

Varnish cache server

  Marten Tjaden
  Darwin Woodka
  benda

@Gargron so then the ddos attack on mastodon.social has nothing to do with stoners.social being down? bc that instance is still down and we were given no heads up. im rebuilding from scratch over here.

  MrShoggoth
  Lena
  DHeadshot's Alt

@Gargron I'm getting 403 errors trying to access the site - am I blocked then? I didn't do anything apart from try to load my timeline while you were down!

  Nameless

@Gargron My conspiracy theory of the moment: Elon rerouted all the API calls this way.

sandywb14

@Gargron Thank you for the transparency.

Hikarii

@Gargron was this related to all the weird Twitter Toots I wasnt following showing up on my dash? I was trying to check if I accidentally followed the hashtag

Thomas H Jones II

@Gargron Need to work with your CDN to at least splash up a failephant when stuff like this happens. The 503 error-page otherwise has no zing.

Steve Wildsmith
Andy K

@Gargron hang in there. Doing great. No complaints.

Aldi80s 🇯🇵 アルディ
Vanitarium

@Gargron
Thank you to all the team‼️🙏🙏🙏🙏

Sarah Collins

@Gargron good luck in your work! 💖

Yashank

@Gargron anyway we can help prevent this in future?

harveen

@Gargron must’ve been some petulant billionaire unhappy that he’s enshittified what he took from others and that he can’t control the narrative. Wonder who that might be ..

harveen

@Gargron someone must’ve been really upset by my post after today’s outage at the bird app.

Pensive™️

@Gargron Is mastodon.social under attack again? The search function is not working for me.

𓃵 fizzily🐐bizina🐐çiya 𓃵

@Gargron

Does it waddle and quack like the RU mafia state?

And they thought turning twtr into their propaganda and terrorist mush via their psycho puppet was going to be enough.

Go Up