3 ms·
The requests wouldn't be synchronized, so probably wouldn't cause a DoS
by jm_l 8y ago
The requests wouldn't be synchronized, so probably wouldn't cause a DoS
- bpicolo 8y agoOnce an hour means they're doing ~30k qps if they have 100 million devices (and traffic is well-distributed, which admittedly is pretty easy to do), though 100 million is potentially an overestimate. Point is, you can't just fire that traffic into the nether / to domains you don't control from IoT devices. Those providers will happily cut off your automated traffic.
- johnchristopher 8y ago> Point is, you can't just fire that traffic into the nether / to domains you don't control from IoT devices. Those providers will happily cut off your automated traffic. Which reminds me: https://news.ycombinator.com/item?id=15911501 https://news.ycombinator.com/item?id=15911501 TP-Link firmware sends six DNS requests and one NTP query every 5 seconds https://www.ctrl.blog/entry/tplink-aggressive-ntp https://www.ctrl.blog/entry/tplink-aggressive-ntp
- puzzle 8y agoEven if they don't start synchronized, something as simple as a hiccup on the receiving side of all such pings would make them more and more synchronized over time. Such is the life of anyone operating large sites.
- convolvatron 8y agothis is a really good paper on this effect - https://ee.lbl.gov/papers/sync_94.pdf they suggest factoring out the service time from the timer scheduling to defeat it. a generally more robust approach is to select a timeout interval from a distribution.