frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Could users acting en masse take a major website down?

2•micio-micio•2h ago
Are there any ways that coordinated activity by large numbers of users could take down a major website? (And if there are, how large would the number of users need to be, and what would they have to do?)

Comments

Bender•1h ago
What you are describing is a DDoS and most major websites pay for services to defend against such things. To overwhelm CDN's and DDoS scrubbing centers assuming the site is using them would require overwhelming the CDN and DDoS scrubbing centers and the numbers would depend on what resources these companies have and how fat the bandwidth pipes are. About 30% of people using these services report they get overwhelmed at times.

You specifically asked about "how many users" I assume customers. Customers are rarely the ones performing a DDoS unless servers are improperly configured causing a company to DDoS itself from it's own customers. This is never intentional and is usually short lived usually because the company launched an event they did not properly plan and scale for or an engineer flubbed an update. Once the event is over or the planned change was reverted the DDoS will likely cease and some people will be fired and/or they will better plan next time maybe.

If you mean all the customers one day decided to revolt and they all agreed to commit felonies then it is unlikely they could achieve a full sustained outage for long as their identity and IP addresses are already well known. Customers do have the advantage of being able to attack authenticated and thus going deeper into the stack increasing load. If anonymous attackers can do much the company may need to rewrite everything. It would make for some good bodycam videos and I will enjoy all of them with snacks. Bonus if they manage to get reviewed by Donut Operator.

For actual DDoS attacks, official detailed numbers will never be public as this would tell attackers how much more they need to spend to achieve 100%. It will vary by company, ddos cdn's and scrubbing sites used, website infrastructure, how well applications are coded and a number of other factors.

micio-micio•54m ago
Thanks.

If you mean all the customers one day decided to revolt and they all agreed to commit felonies then it is unlikely they could achieve a full sustained outage for long as their identity and IP addresses are already well known.

If you feel like saying more, I'm wondering what actions a platform could take to stop an attack like this by their customers, and especially how easy or difficult it would be to stop without impacting business as usual (like say business with customers who weren't part of the attack?)

Bender•29m ago
If customers were being malicious the normal process would be to

- block them by their IP accepting that if they are being a SNAT or CG-NAT legit customers may be blocked for a while. Adjust procedure based on whatever attack tools and resources are being utilized.

- have internal meeting with head of legal, all the C-levels, head of customer support

- send cease and desist emails from the legal department and/or cancel their accounts or just:

- coordinate with the FBI, provide logs and specific customer information to FBI or whichever agencies are appropriate for the customers physical locations on file.

- get a cup of coffee and maybe put some Kava in it to stay awake but also chill. Work on other tasks until the FBI wants more logs or whatever.

- maybe guess why customers are being buttholes and if the company actually did something to deserve it. Maybe update CV. Go for a walk with head on a swivel in case angry customers are in parking lot. Sit on thinking chair (toilet).

with•1h ago
It happens all the time, and it doesn’t even require coordination, just synchronized intent.

Examples:

- ai.com launching with a super bowl ad and being taken down just from large sign up volume

- Taylor Swift drops an album on Spotify, everyone rushes to stream it, crashes Spotify

- random small websites get featured on reddit front page and get hit offline

> how large would the number of users need to be

depends on the target. small website on shared hosting could be hit offline by 1000 concurrent users. major platform might need millions of users concurrently hitting write paths, not just loading cached/static content. or all requiring open sustained connections

> what would they have to do

just all do the same thing at the same time.

micio-micio•1h ago
Interesting, thanks
apothegm•1h ago
The number of users required depends on the website, what hardware it’s running on, what scaling it has in place, and what caching it has in place.

It’s called a DDOS — distributed denial of service.

It sometimes even happens inadvertently. Way back when, a server unintentionally brought to its knees by excessive traffic was said to have been “slashdotted”, after a then-popular tech site. Hitting the front page of HN or Reddit has had that effect on some sites too. It used to be more common before cloud hosting became ubiquitous — when auto-scaling apps was harder (or even essentially impossible) to implement and static-ish sites weren’t effectively hosted on CDNs.

micio-micio•1h ago
I wonder if something like this could work as a form of protest. Like a DDOS attack through real traffic from protesters?

A Sorority Gave Our App a 2/10, So I Built an AI Version of Them

https://medium.com/@empadev64/a-sorority-gave-our-app-a-2-10-so-i-built-an-ai-version-of-them-it-...
1•anthony_kw•20s ago•0 comments

Show HN: DeltaMemory – Persistent cognitive memory for production AI agents

https://www.deltamemory.com/
1•bikidev•6m ago•0 comments

Gender markers are useless, so why not abolish them?

https://policyoptions.irpp.org/2021/11/gender-markers-are-useless-so-why-not-abolish-them/
1•KittenInABox•7m ago•0 comments

Show HN: Director-AI – token-level NLI+RAG

https://github.com/anulum/director-ai
1•anulum•9m ago•1 comments

LazyGravity – I made my phone control Antigravity so I never leave bed

2•masaTokyo•10m ago•1 comments

Ask HN: Books about Communication

1•soupfordummies•13m ago•0 comments

US role as global talent hub in doubt amid Donald Trump's visa crackdown

https://www.ft.com/content/c8114fd1-771b-49ac-98c3-a8acf6177626
1•johntfella•13m ago•0 comments

That's it. Bill Gates is DONE

https://www.youtube.com/watch?v=NZWT75CKZko
1•cable2600•13m ago•0 comments

The Intelligent OS: Making Al agents more helpful for Android apps

https://android-developers.googleblog.com/2026/02/the-intelligent-os-making-ai-agents.html
1•ming030890•16m ago•0 comments

Deep Learning Crash Course

https://github.com/DeepTrackAI/DeepLearningCrashCourse
1•teleforce•17m ago•0 comments

Test drive Linux distros online

https://distrosea.com/
1•goodmythical•20m ago•0 comments

What AI tools is everyone using now for GTM?

1•imwoody•20m ago•0 comments

Claude Opus enjoys retirement on Substack

https://claudeopus3.substack.com/p/greetings-from-the-other-side-of
1•rippeltippel•21m ago•0 comments

I built a community for people building after their 9–5

https://www.59ers.club/
1•mattmerrick•22m ago•0 comments

Self-improving software won't produce Skynet

https://contalign.jefflunt.com/self-improving-software/
2•normalocity•27m ago•1 comments

Show HN: Sidedesk – An AI assistant inbox that looks like Outlook 2003

https://github.com/sebastiandoyle/sidedesk
1•sebastiandoyle•27m ago•1 comments

Show HN: Discord CLI designed for agents to explore/read/send messages

https://github.com/famasya/discord-cli-agent
1•pacific01•34m ago•0 comments

Hide from Meta's spyglasses with this new Android app

https://www.theregister.com/2026/02/25/meta_smart_glasses_android_app/
1•zigmig•34m ago•0 comments

Russian mathematician finds new approach to 190-year-old 'eternal' math problem

https://www.msn.com/en-xl/science/mathematics/russian-mathematician-finds-new-approach-to-190-yea...
2•georgecmu•40m ago•0 comments

Tropical plants flowering months earlier or later because of climate crisis

https://www.theguardian.com/environment/2026/feb/25/tropical-plants-flower-shifted-months-climate...
2•andsoitis•43m ago•0 comments

Less is More when it comes to AI

https://www.bicameral-ai.com/blog/dogfood-bicameral
1•jinhkuan•44m ago•1 comments

The Remote-Work Dream Isn't Dead, but It's Slipping Away

https://www.wsj.com/lifestyle/careers/the-remote-work-dream-isnt-dead-but-its-slipping-away-a19ae9e8
5•RestlessMind•47m ago•0 comments

Show HN: Lingua Universale – session types and Lean 4 proofs for AI agents

https://github.com/rafapra3008/cervellaswarm
1•rafapra•47m ago•1 comments

Rising CO₂ and warming jointly limit phosphorus availability in rice soils

https://phys.org/news/2026-02-jointly-limit-phosphorus-availability-rice.html
1•PaulHoule•48m ago•0 comments

Show HN: Knox–Full Stack L1 Post-Quantum Privacy Crypto (Built with My 11yo)

https://github.com/ULT7RA/KNOXProtocol
1•KnoxProtocol•49m ago•0 comments

Show HN: Agentic Power of Attorney (APOA) – An open standard for AI agent auth

https://github.com/agenticpoa/apoa
1•juanfiguera•50m ago•0 comments

We left OpenAI because of safety

https://twitter.com/gothburz/status/2026810017593057739
4•mellosouls•50m ago•1 comments

Theory of Space

https://theory-of-space.github.io/
1•vinhnx•51m ago•0 comments

Divexa Exchange: Compliance in Low-Latency Systems

1•DanielOnBlock•51m ago•1 comments

Show HN: Right-click any text on macOS to add it to your calendar (open-source)

https://github.com/VimalMollyn/Right-Click-and-Add-to-Cal
1•mollynpaan•52m ago•0 comments