5 ms·
It can easily do it, the point is that doing this makes it more expensive to spam your site. Let's say normally, it takes 1 second to post, now it might take 10
by Jernik 7y ago
It can easily do it, the point is that doing this makes it more expensive to spam your site. Let's say normally, it takes 1 second to post, now it might take 10 secs. Now you're spending 10x as much to post a comment or form, etc
- DJBunnies 7y agoAnd pushing these costs to legit users.
- unilynx 7y agoJust like hashcash trying to prevent mailspam... you just need a bigger botnet. Spammers were never spending their own energy/money. Well, at least there are less CPU cycles left to ddos wikipedia I guess..
- rolltiide 7y agouhmmmm okay. I think my compute instances could handle that. the way I pay for them (heroku) usually results in underutilized resources which could accommodate this level of computation.
- yellowapple 7y agoWouldn't it be more effective to throttle on the server side? You could have the server just artificially take 10 seconds to respond to the request and get the same effect.
- 1mbsite 7y agoNot necessarily. Somebody can spam your form from multiple hosts. If you enforce a proof of work they will all need to work for it.
- yellowapple 7y agoBut somebody can also do the proof of work from multiple hosts (or parallelized on the same host, e.g. with GPU computation). How does a proof-of-work in this case actually do more than just throttling the server's responses?
- 1mbsite 7y agoBecause there’s more work involved.
- yellowapple 7y agoOkay, but that's kinda like saying eating healthy is good because you get to deprive oneself of donuts: that is, I feel like it's mixing up the cost and benefit. The point of the work is (from what I'm understanding here) to make it less feasible for bots to flood a server with requests, but doing the throttling server-side would have the exact same effect more consistently (i.e. in a way that's not easily evaded by GPU/FPGA/ASIC acceleration and doesn't punish normal users).