3 ms·
The real solution here is that the blog owner needs to turn off security for their RSS feed URLs. Cloudflare could make this easier if it detected that they ha
by Navarr 10y ago
The real solution here is that the blog owner needs to turn off security for their RSS feed URLs.
Cloudflare could make this easier if it detected that they had an RSS feed and offered a suggestion, via email or the browser (or both) that was like "Create a security exception for your RSS feed"
- LeifCarrotson 10y agoNo, the blog owner still needs protection on the RSS feeds. If they publish something that offends someone with a botnet, and have an exception for the RSS feed, the offended someone will just attack the feed to take down the site. The real solution is for the feed reader to contain better error handling.
- afandian 10y agoYou can surely do DDOS protection on a particular URL without a bot detector.
- LeifCarrotson 10y agoSure. For example, throw a 503 on requesting that URL, or present a captcha. But then feed readers that get caught in the DDOS protection, can't do the captcha, and don't handle errors will fail to get the feed.
- LeifCarrotson 10y agoSure. For example, throw a 503 on requesting that URL, or present a captcha. But then feed readers that get caught in the DDOS protection, can't do the captcha, and don't handle errors will fail to get the feed.