Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
What Happened with the DDoS Attacks That Took Down X (wired.com)
27 points by thunderbong 3 months ago | hide | past | favorite | 7 comments



> but independent security researcher Kevin Beaumont and other analysts see evidence that some X origin servers, which respond to web requests, weren't properly secured behind the company's Cloudflare DDoS protection and were publicly visible. As a result, attackers could target them directly. X has since secured the servers.

X forgetting to put some important servers behind Cloudflare is some very important context

> But one researcher from a prominent firm, who requested anonymity because they are not authorized to speak about X, noted that they did not even see Ukraine in the breakdown of the top 20 IP address origins involved in the X attacks.

Traffic from Ukraine was present, but not anywhere near the top of the list. Also some important context.


Don’t worry, the same crack team that can’t figure out how to properly set up a CDN for a second rate social media website are totally competent to fix the $4t federal government.


Musk has adapted Trump's and Russia's policy: never tell the truth. Being honest is a weakness.

This is of course wrong. Obviously ethically but also practically. By now we already know that everything peoole like this say is probably not true.


Given that Putin and Trump are firmly in power and Musk is the most wealthy person on earth, I’d say that strategy works pretty well.

Destroying the truth helps authoritarians drown out opposing views


What's with topics on this matter going off the top page this fast? The services had been intermittent for last couple days, and the current top link goes to Twitter so it's clear that everyone is on it. It warrants a lot more commentaries. Feels like divide-and-conquer is going on.

0: https://news.ycombinator.com/item?id=43332658


So it seems neither traffic came from Ukraine nor Dark Storm was probably behind the attack. The plot thickens!

https://www.bitsight.com/blog/massive-ddos-cyber-fog


Thought it was strange that X got hit when they are using Cloudflare. Not much competence left at X I guess. What more have they done? No encryption between CF and origins?

The hackers can probably just launch a new attack from CF. Not like X is checking the headers if they failed with the basic setup.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: