Steemit is undergoing a DDOS service denial attack but your wallet is safe...

in #steemit7 years ago (edited)

The following is a chat room excerpt which explains why steemit.com is down right now, has been since yesterday, what you can do about it to keep steeming on and why your wallet and data are still safe. It has been edited to remove other user's names and unrelated, interleaved messages from the chat room, but I wanted to get something posted, without delay to keep my friends informed, and not bother to clean it up too much to save time to the wire on getting this out.

POST PUBLICATION EDIT/UPDATE FROM ANOTHER ANON CHAT USER:

apparently, "The devs attempted to add a feature to track user interactions on the site, it relied on a third party, and when that service went down, it caused an infinite loop of requests on the chain, this caused the server for Steemit.com to fail. They are working to roll-back the changes and stabilize the web-server nodes."

THEY CAUSED THEIR OWN DDOS ON THEMSELVES. UGH! Read on for assurances of the safety of your wallet and data, as well as alternatives you can use to keep on steeming.

SirCork-Today at 8:17 AM

I was just notified seconds ago that steemit has been attacked once again by a DDOS attack DDOS = Distributed Denial Of Service

This is when bot slave networks are used to send massive amounts of traffic to an endpoint, in this case steemit RPC nodes, which interface the blogging site to the block chain and overwhelm it's service capabilities

it's telling a webserver that might be able to handle a million hits a minute, to send a trillion - hypothetical example numbers aside in layman's terms ^

Service will be intermittent until the attack subsides or other mitigation can occur, such as re-routing services to backup devices and alternate DNS routes.

don't worry, the block chain is unaffected and all other sites besides steemit seem to functional under normal conditions.

all that is affected is the poorly executed and relatively unprotected steemit.com user interface. These guys have so many amateur oversights in this user interface and across the user experience that it really is unfathomable at times to be how it can be so bad. It's like they pay beginner developers to build this thing.

Things like having no user confirmations on important interactions (literally one short line of code would be better than the none they have now, to ask a user to confirm a submission button click on say a wallet transaction or a witness vote/unvote)

Even putting up a quick "hey, we are under attack or maintenance" type page seems to escape these guy's capabilities. I know first year developers who do a better job. Ugh, it's depressing.

SirCork-Today at 8:26 AM

so if you are super in need of a read or write fix, busy.org and chainbb.com remain functional

also if you are super nerdy you can also use alternate RPC nodes, with the mobile esteem app

You can use eSteem application with any live websocket for example: wss://gtg.steem.house:8090, wss://seed.bitcoiner.me, wss://steemd.privex.io or many others.

The attack is only on steemit nodes apparently.

I don't use esteem, busy or chainbb, but I can read there, and news channels will probably continue to have blog posts about the issue so you can follow along

[Another user asks for laymens terms]

SirCork-Today at 8:28 AM

there are machines listening to requests/sending responses to the usersa bot army shows up and starts making hundreds of thousands of requests a secondand the servers melt downtrying to answerswer each you are going to quickly be unable to serve them all

AnonChatUser-Today at 8:29 AM

you should turn that into an article SirCork

SirCork-Today at 8:29 AM

there are machines listening to requests/sending responses to the users

a bot army shows up and starts making hundreds of thousands of requests a second and the servers melt down trying to answer

AnonChatUser-Today at 8:29 AM

You realize everyone who isn't techy will be asking. And that explanation makes a lot of sense. So write a DDOS for dummies article and post it when things work.

SirCork-Today at 8:29 AM

no, I don't normally write technical articles for good reason, I do NOT want that reputation here because this stuff makes even MY eyes glaze over and I have been the go-to guy for newb questions for 35 years.

I'm over it.

AnonChatUser-Today at 8:30 AM

but your explanation wasn't technical. That's what I mean.Ah, yes.

SirCork-Today at 8:30 AM

yeah, that's how I makes my money

AnonChatUser-Today at 8:30 AM

We won't make you become that. No worries

SirCork-Today at 8:31 AM

as such, ugh. so thanks, please don't. :)

Sort:  

Thats a real info, I am adding your post link to my post :]

Good deal bottybuddy! Go for it. The notification about your own post was helpful in confirming my suspicions about the event in progress.I used to work for a company that is the world's largest firm providing services to prevent and mitigate DDOS attacks, so I sort of recognized the pattern right away. Your article and access to an inside developer before I bothered the one's I know myself, confirmed it. Thus I wanted to get this out to my people's as fast as I could to belay concerns about their wallets and data. Thanks botty!!!

Ha! I'm only a newb because you're either older than me or started coding at the age of 5. Doesn't hurt so bad when you state 35 years!( the problem is always between the keyboard and the chair)😅

Why is this post downvoted? and by @sneak?

Good question for @sneak, the Chief Troll Officer of Steemit, Inc.

thanks for a simple explanation @sircork :) this is very helpful!

Thanks @sircork

God damned down vote!
Getting a bullshit downvote is a lot like beeing on youtube or farcebook and talking about something they don't like. So much for free speech, eh?

LOL, Even more ironic is that he is the CTO of steemit, inc. ;)

Haha my dear friend @sircork. Stay not using eSteem, busy or chainbb and come here besides me to watch the amusing spectacle that's going on from the balcony where I am now. From here we can catch sight it all.

I've been here uninterruptedly logged in within 'steemit' since 00:15am hrs [GMT -4:30] today. Yes all night long. And I even wrote a funny binnacle from here, about all the events that have been happening since the start while sipping a margarita also.

Yeah! enter, enter without fear mate. I've already given you the keys to find some awareness, wisdom & laughter. Just click the blue text above and you'll know. }:)

apparently, "The devs attempted to add a feature to track user interactions on the site, it relied on a third party, and when that service went down, it caused an infinite loop of requests on the chain, this caused the server for Steemit.com to fail. They are working to roll-back the changes and stabilize the web-server nodes."

This is not accurate information.

@sneak Maybe spend your time preventing and mitigating the issues at hand, rather than flagging minnows and swinging peen? Or fixing UX/UI errors, omissions and issues that plague the interface? Wouldn't that be a more productive use of your time Mr "No Class Warfare?" Or you know, do you just prefer making yourself look sad in front of all the users who will see this flag? If you think I CARE about your flag, your delusions are misguided. ;) I don't earn my income here, but you do, so go do it maybe?

¡LoL! Perhaps, if by chance... ¿Couldn't be this possible that this "Fabric" in that pre-announced brand new Steem Blockchain Fabric got frayed and ended up disentangled too much in the wrong hands?

Since my vote didn't help your post, I put it on this comment instead.

Thank you very much. Very kind of you.

His use of flags is really starting to tick me off. This is a site that promotes the idea of no censorship, but he uses his power to censor anything he doesn't like.

Yeah well there seems to be a lot of inexperienced children run amok at steemit inc and elsewhere on the site.

True. steemit is mirroring life it would seem. Fortunately that also means there are a lot of incredible people here as well :)

well, the response to inaccurate information is to provide accurate information instead of responding with a spiteful and childish downvote

From what I've seen that's the best he can do. Maybe jealous cause I've got nearly as many followers, 4x the amount of posts and time spent actually being visible here and realizes I don't give a shit who he thinks he is, my career history also crushes his by about 30 years? Meh. Haters gonna hate, they rarely add value. If he was about value, the site would be in much better condition. It's his optics at risk, not mine.

small mind ... small person

Small... something... ;)

LMAO

I was very surprised to see @sircork get a downvote! Remove that flag please. You need to keep the users informed with accurate and up to date information about what's going on, and this should be done with a "News" button on the website. There's too much happening in secrecy, we have the right to know.

If you know it better, would you mind to tell us what is the accurate information?

This post has been ranked within the top 50 most undervalued posts in the second half of Oct 06. We estimate that this post is undervalued by $17.49 as compared to a scenario in which every voter had an equal say.

See the full rankings and details in The Daily Tribune: Oct 06 - Part II. You can also read about some of our methodology, data analysis and technical details in our initial post.

If you are the author and would prefer not to receive these comments, simply reply "Stop" to this comment.

If it was caused by a third-party service going down without proper exception handling in the code... that's not a DDOS. Its a nice generic scapegoat to use though without showing facts.

Thanks for your input on the reported anonymous quote.

Congratulations @sircork! You have completed some achievement on Steemit and have been rewarded with new badge(s) :

Award for the number of comments received

Click on any badge to view your own Board of Honor on SteemitBoard.
For more information about SteemitBoard, click here

If you no longer want to receive notifications, reply to this comment with the word STOP

By upvoting this notification, you can help all Steemit users. Learn how here!

Coin Marketplace

STEEM 0.28
TRX 0.13
JST 0.032
BTC 60896.54
ETH 2918.31
USDT 1.00
SBD 3.61