3 ms·
> Going with the mask analogy, they should instead check if a person is brute forcing lock combinations. Maybe even condition on the fact that they're wearing a
by bskap 11y ago
> Going with the mask analogy, they should instead check if a person is brute forcing lock combinations. Maybe even condition on the fact that they're wearing a mask.
That's what they're doing. They are seeing brute forcing come from a bunch of IPs and they're blocking those. What do you expect them to block on? The people using the anonymous service voluntarily identifying themselves on every request (cookies, browser fingerprinting, or pretty much anything else coming from the client side that can be faked)?
- lqdc13 11y agoInstead of having IP-based reputation system, that persists for quite a while, they could have a time limit per IP for specific kinds of requests. Like if you fail to log in to a site, 2^(attempts) timeout from that IP for that page only. Can also integrate a combination of request headers. Sure, it's still IP-based reputation, but it doesn't persist and is much less intrusive. Most sites require specific cookies on consecutive requests, and such blocking should be on the app side only. There are solutions in each case and all of them are harder than IP-based blocking. However, in the interest of privacy, they should adopt these more nuanced solutions.
- bskap 11y agoSo a single IP address can DDoS each page of a website for a little while before CloudFlare blocks them? That makes the whole protection pretty useless. I guess it would stop someone from brute-forcing password attempts, but that's not the only thing they're trying to protect against here.
- lqdc13 11y agoNot necessarily. These work in combination. If they're requesting specific type of content like images or some weird request that queries DB, these would be grouped together. What I'm saying is gather more information for each request and use it more wisely to expire IP reputation quicker - within minutes as opposed to months. The DDoS problem is actually easier than the rest because you need a large volume of requests to do anything. Usually these requests are very similar, come in rapid succession and come from the same bunch of IPs. Edit: Going with the mask analogy again, it's like you see 1000 masked people rush into a bar and block the entrance with their bodies. Is the solution really to ban wearing masks everywhere?
- mhluongo 11y agoA single IP can't "DDoS" anything.
- jessaustin 11y agoHa! Seriously though if some set of IPs is DoSing then they have to take action against at least some of the IPs in the set.