this post was submitted on 15 Jul 2023
257 points (98.5% liked)

Lemmy

12572 readers
1 users here now

Everything about Lemmy; bugs, gripes, praises, and advocacy.

For discussion about the lemmy.ml instance, go to !meta@lemmy.ml.

founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] axsyse@lemmy.sdf.org 6 points 1 year ago (1 children)

DDOS is a pretty brute-force attack, so it isn't typically relying on a vulnerability per se. Pretty much the only way to mitigate it is to have large enough infrastructure that you can detect and filter out its gobs of spammy traffic, which no Lemmy instances (at least at the moment) can really practically have. They could potentially use a service like CloudFlare, which does have that infrastructure in place, but that can be expensive. I'd imagine CloudFlare (or a competitor) is probably the best solution they can go with, at least in the short-term.

Yeah, for this one I was meaning the alternate account part. But this one is just the latest in a string, most of which were vulnerabilities or flaws in the architecture. I could have been more clear though.