4 ms·
Oh noes. Someone can keep downloading data from a server. Someone call the cops. This is a big nothing-burger. The "attacker" has to actively sustain downloadi
by globalreset 3y ago
Oh noes. Someone can keep downloading data from a server. Someone call the cops.
This is a big nothing-burger. The "attacker" has to actively sustain downloading the data being requested. No amplification, no anything making it anything but a nuisance. Just a lamer that discovered that they can keep making requests in a loop in a Python script.
Sure, some per-IP rate-limiting might be desirable there (but has to be balanced against new nodes being able to download the history), but any service exposing data on the public Internet can be DDoSed by just making requests to it from multiple IPs, and that's why so many companies hide behind Cloudflare.
The total rate limiting seems to be already implemented: https://notatether.com/academy/how-to-limit-bandwidth-of-bitcoin-core-full-guide/ https://notatether.com/academy/how-to-limit-bandwidth-of-bit...
This "attack" might rake some fees on people hosting public nodes in the cloud (just like about any http server, S3 bucket etc.), but that's about it. Lots of nodes don't accept incoming connections, communicate via Tor, network relays, etc. so this has absolutely no chance of making any dent in the network as a whole.
- pbear2k23 3y agothe conclusion of your argument is "this has absolutely no chance of making any dent in the network as a whole" which is faulty. much of the network is hosted by providers that charge for upstream overage: https://bitnodes.io/nodes/?q=ipv4#networks-tab https://bitnodes.io/nodes/?q=ipv4#networks-tab. if a pool's full node is tcp/8333 exposed or a conventional full node is attacked on a vuln host there will be financial/operational consequences. this attack is a "nothing-burger" until botnet skids demonstrate otherwise.