@mkljczk@mstdn.io

On the one hand its Gargrons right to allow whatever services he wants to access his API. This is no different than blocking a fediverse server. That said I think its unfair to call this a DDOS or even a misuse of the API.. In fact I'd say this is the very purpose of an activity pub endpoint, so anyone can access the data and interoperate with the server as they see fit.

@xorowl@mastodon.technology @jimpjorps @Gargron

@freemo @mkljczk @xorowl @jimpjorps It's DDoS when their software is coded in such a way that many IPs hit the same endpoints over and over in frequent fashion when they could simply cache the results

@Gargron

Fair, if a single client is hitting it excessively then it should be cached and isnt good etiquette for sure. Not quite sure I'd call it a DDoS but still, its bad design.

@mkljczk@mstdn.io @xorowl@mastodon.technology @jimpjorps

@freemo @mkljczk @xorowl @jimpjorps Again, it's distributed DoS because they release this software (a game mod) to end-users whose IPs are the ones hitting the endpoints. As far as I understand, anyway. I'm currently analyzing the log files to find out how many unique IPs the requests are coming from.

@Gargron @freemo @mkljczk @xorowl @jimpjorps or, put differently:

Is it distributed? Yes.

Does it potentially lead to denial of service (through resource exhastion)? Yes.

Sounds about right.

@rysiek

I cant speak to Gargron's setup but I think most setups would be able to handle 3400 RPM on the outbox without even batting an eye.

Also by that logic if too many people start using mastodon clients on their phone or desktop then that is a DDoS since enough of them are distributed and would lead to resource depletion.

@Gargron @mkljczk@mstdn.io @xorowl@mastodon.technology @jimpjorps

@freemo @Gargron @mkljczk @xorowl @jimpjorps he did mention 24000rpm (400rps) before.

Also, it's not 3400rpm, it's 3400rpm from a single small group of users. With all other requests being handled, that might be enough to create issues.

And finally, if the admin of an instance says this is too much, it's too much. If they want they can run their own servers, instead of getting high on their entitlement.

Follow

@rysiek

I already said in my first response he is entierly justified in blocking whoever he wants, for any reason, and this is as good as any. So we are in agreement.

@Gargron @mkljczk@mstdn.io @xorowl@mastodon.technology @jimpjorps

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.