3 ms·
I'll bite: sliding windows are a pain, if you hit them by accident they result in a weird self-DoS. Why not token bucket? It's a simpler algorithm to implement
by bcoates 10y ago
I'll bite: sliding windows are a pain, if you hit them by accident they result in a weird self-DoS. Why not token bucket? It's a simpler algorithm to implement and less pain for the client.
If I'm unaware of these limits and use them up all at once, I'm locked out for a week instead of having to wait 1/rate to issue just one more.
- j4cob 10y ago(Let's Encrypt engineer) Token bucket is a good idea, and I agree that it would make the user experience of hitting rate limits less onerous. We implemented sliding windows because they were straightforward to implement based on our long-term database state. I'll do some thinking about whether we can emulate a token bucket style on top of that without having to add another source of truth for rate limit information.
- nickpsecurity 10y agoHas anyone published something about the performance, scaling, and price of your HSM's? I'd like a link to it if it's available.