6 ms·
Canonical/Ubuntu have been under DDoS
- Faaak 5mo agoTinfoil hat mode: a competitor wants to exploit copy.fail on some ubuntu servers, and is DDoSing canonical so that they can't update and thus patch the vuln
- kubb 5mo agos/competitor/intelligence services/
- ramon156 5mo ago+1, it hasnt even been 24 hours and I already see these stupid CyberSec companies trying to squeeze themselves between this.
- bouncycastle 5mo agoSeems reasonable to assume it's something to do with the recently publicized exploits. More likely, this could be an extortion attempt by criminals rather than a competitor.
- yallpendantools 5mo agoDouble tinfoil hat mode: an attacker learned of my plan to finally update my personal computer out of 20.04 today and is DDoSing canonical so I can't do that and I remain vulnerable to the backdoors they've found. The plot thickens...
- pixel_popping 5mo agoyou are the center of all this, I knew it.
- touwer 5mo agowhy a competitor? Criminals, secret services, country adversaries...
- bjackman 5mo agoIf you can access AF_ALG on a server you don't need to do shenanigans like that. It's much easier to just find another bug and exploit that one instead. The copy.fail website is very silly, it is not a special bug. If anyone gets compromised by that vuln their node architecture was broken anyway, patching copy.fail doesn't help.
- mustardo 5mo agoI thought copy.fail is a privelage escalation exploit, become root from a regular user? Am I missing something? How would "node architecture" make people vulnerable to this? You have to have shell access to a victim first right? Or am I missing something?
- bjackman 5mo agoYeah you need native code execution, and if you have AF_ALG access there is clearly no sandboxing in place. At that point it's game over on Linux, there are too many bugs. Even if you fix all the known ones in the current kernel, by the time the version with those fixes is qualified and released (not to mention, the machine must reboot), new LPEs have been discovered.
- eggprices 5mo agoTo convince me Linux is full of kernel LPE bugs, can you share some of the bugs?
- ece 5mo agohttps://gtfobins.org https://gtfobins.org
- bjackman 5mo agoLook at kCTF results. Look at the CVE database. Most of those UAFs are LPE. Many of the OOBs and many of the race conditions too. These are fixed in Linus' master but you are running an old kernel. Then look at the KASAN reports on the syzkaller dashboard. Many of them are LPE. Many of the WARNs and crashes are revealing and underlying bugs that is also an LPE. Most of these never get fixed. Then try pointing your LLM at the codebase and saying "find an LPE". It will find as many as you want (you will exhaust your tokens long before it stops finding bugs). 99.99% of them will be bogus so you need a way to evaluate them at scale, currently this is the weakest approach but we'll get better at it. I can't actually point you to a list of confirmed LPEs coz the only way they get confirmed is when someone exploits them, but there aren't enough exploit authors to do this for all of them. If inference gets really cheap and someone builds a really good agent harness we might start to see it get automated at some point.
- ls612 5mo agoIt isn’t a competitor it is Iran.
- Wxc2jjJmST9XWWL 5mo agoNoticed it because snap didn't work, snap has its own status page just fyi: https://status.snapcraft.io/ https://status.snapcraft.io/
- ForHackernews 5mo agoFrustrating because the Slack snap is broken so every day you have to downgrade it and I guess you can't without connectivity. This might be the incentive I need to finally purge snap.
- esseph 5mo agoJust move to flatpak, much nicer to deal with
- lproven 5mo agoIn my testing I find the exact reverse. I much prefer snap to flatpak.
- esseph 5mo agoSnap is mostly limited to Ubuntu and has to run as a daemon. Flatpak gives me cross-platform/cross-distro software directly/certified by the project or company that has additional security sandboxing and doesn't open up potential security issues. I don't have to wait for a distro package, and yet there are no system integration concerns. It also works great for atomic distros (SilverBlue, etc)
- someperson 5mo agoI like to imagine it's returning a 500 error response asking you to email rhonda@ubuntu.com
- corvad 5mo agoThis seems to be pretty targeted, and with the services affected like livepatch and such this could indeed be an actor DDoSing to avoid patches rolling out for copy.fail
- TonyTrapp 5mo agoWhile the timing with the copy.fail patches mentioned by a few comments here seems suspicious indeed, I have seen this repeating over the last few weeks: packages.ubuntu.com was hardly reachable on some days, causing apt-get to take forever to update the system. They have been struggling hard recently, it seems. Best of luck to the people having to deal with this mess on a holiday!
- necovek 5mo agoThe point of coincidental timing with copy.fail patches is that by DDoSing an upgrade mechanism for one of most popular distributions, you extend the time window certain systems remain vulnerable in order to exploit them.
- TonyTrapp 5mo agoThe point is that these apparent DDoSes have been going on for weeks, they are not necessarily related to copy.fail.
- nullpoint420 5mo agoMakes you wonder if certain parties were tipped off early
- jollymonATX 5mo agoWe are so broken as society ddos'n ubuntu is now a thing.
- piker 5mo agoThough this outage may be more related to the copy.fail upgrade cycle, it reminds me of a thought I've had recently in respect of agents. In the UK they have this issue called "TV pickup" (https://en.wikipedia.org/wiki/TV_pickup https://en.wikipedia.org/wiki/TV_pickup). TV pickup is where everyone in the UK watching a popular TV show gets up to boil a high-powered tea kettle at the same time on an ad break. This causes a temporary surge in electricity demand and leads to real outages. It was a mystery at first but now is accounted for. I suspect the global internet is facing an "agent pickup" problem where significant changes (e.g., releases of new frontier models or new package versions) puts unpredictable pressure on arbitrary infrastructure as millions of distributed agents act to address the change simultaneously.
- sig-11 5mo agoWe're at the stage where we blame AI for anything as a first reaction? (Love the tv pickup story. I also thought of that, in other situations)
- Hnrobert42 5mo agoIndeed. It is far more likely to be the copyfail issue.
- piker 5mo agoI wasn't blaming this issue on that in particular, just making an more general observation in line with the post. I'll make that clearer.
- Yoric 5mo agoWell, that and the rush to upgrade for copy.fail. Has Ubuntu published patches yet?
- jamessb 5mo agoYes, but I can currently only load the page about them via the Wayback Machine: https://web.archive.org/web/20260430191621/https://ubuntu.com/blog/copy-fail-vulnerability-fixes-available https://web.archive.org/web/20260430191621/https://ubuntu.co...
- deleted 5mo ago[deleted]
- mayhemducks 5mo agoMaybe they could use this DDoS attack as their 17th round technical interview. Any candidate who successfully mitigates the attack would then make it to the 18th round. Win win!
- Yoric 5mo agoDo they finally meet a human being with an explanation on the position on the 18th round?
- fragmede 5mo agoDepends on their high school GPA.
- kps 5mo agoI did really well in Kindergarten, so I made it to the 22nd round.
- irishcoffee 5mo agoThey told me my grandpa was too dumb at round 47. I felt like I was close.
- jaennaet 5mo agoI got all the way to round 53, but it turned out that one of my semiaquatic tetrapod ancestors from the Carboniferous Period didn't perform on land as well as they would have liked, so that was it for me.
- mayhemducks 5mo ago5 internet points to you sir.
- joecot 5mo agoIs their interview process Dungeon Crawler Carl? Do you just apply to work at Canonical, and at the 3rd interview you get to pick what position you're applying for?
- ddactic 5mo ago[flagged]
- sidewndr46 5mo agoIt's almost certainly related to preventing the roll out of copy.fail fixes. Someone held the capability in reserve until they had a good reason to use it.
- dang 5mo agoRelated ongoing thread: Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down - https://news.ycombinator.com/item?id=47975729 https://news.ycombinator.com/item?id=47975729 - May 2026 (59 comments)
- SilentM68 5mo agoCould this DDoS be affecting some components of https://ppa.launchpadcontent.net https://ppa.launchpadcontent.net? I know they're supposed to be down and up again, but I still get errors when I update Ubuntu :(
- bastardoperator 5mo agoNo mitigation can stop Aisuru. Let's hope it's not that because the only end in sight is them getting bored and moving on to the next victim.
- deleted 5mo ago[deleted]
- Bender 5mo agoAnyone from Canonical shared any pcaps of the attack yet? Or perhaps a summary of packet types, sizes, payloads, TCP/IP header characteristics? State table statistics?
- nullpoint420 5mo agoI’d be surprised if they had this amount of observability info.
- securicat 5mo agoExplains why I needed to torrent Ubuntu 26.04 today. Even navigating to the alternative/mirror page to grab the torrent file was painful.
- drillsteps5 5mo agoAnother wave today (5/2/2026), launchpadcontent.net is down...
- lproven 5mo agoAlso here: https://news.ycombinator.com/item?id=47989372 https://news.ycombinator.com/item?id=47989372