4 ms·
It probably does. The issue is proxy. This is the downside to TLS and letsencrypt. Because man in the middle is a thing. Being a fediverse application the p
by sumtechguy 2y ago
It probably does. The issue is proxy. This is the downside to TLS and letsencrypt. Because man in the middle is a thing. Being a fediverse application the proper idea would be for the clients to P2P the data amongst themselves and lighten the load on the originator. However, in this case a link probably should not do that. So therefore it needs to go get the data itself. It is a DDoS were basically one link can magnify to thousands of other clients. Then until those clients are done they will stomp the site. Perhaps there could be a side channel ask from the client 'hey site are you cool with me showing the user a preview of this'? Or 'hey site is it ok if I share a preview of your page'? That would not totally stop the rush of requests. But would at least keep it from a render of the page for a preview. This method is half baked and something I just came up with and seems wrong though. But auto following links is not exactly in spec either.
- BlueTemplar 2y agoHow much MitM is even an issue with link previews, rather than actual links ?
- sumtechguy 2y agoIf I think like an attacker I would say a preview would be an even juicier target. I can basically run something on thousands of peoples computers with zero input from them.
- ehutch79 2y agoTheir site isn't going down from an attack. It's running out of resources for normal operations. It's not even a large amount of traffic. not really.
- BlueTemplar 2y agoWhy would it be about running something, rather than just a paragraph of text and a picture ?
- sumtechguy 2y agoThe thing is you are allowing your client to do things without you saying to do it. That means you trust whoever is sending that link. To render you have to run a bit of JS and grab some other URLs. 'running' is probably not a great term for it. In this case if I were an attacker I can basically cause your mastodon client render without the users doing anything. I would call it a possible attack vector. Instead of the originating client rendering it and sending a picture along with the URL, it is telling the other side 'hey here is a URL' then the client own its own going to get a new snapshot. Some sort of render needs to happen for that picture to be created. In the second case that means if I were a sneaky sort I could send a link out to a group and I know an exploit in the mastadon render code I could cause interesting things to happen. I could also use this to attack sites. If I get into a large enough group I could basically spam the group with a bunch of URLs and cause a DDoS to any victim site I want.
- ehutch79 2y agoNone of that makes sense. What does getting a certificate through let's encrypt have to do with the server getting overwhelemed? It's a thing that happens once to renew a cert every couple months. The performance hit of https on a modern server is negligable. The performance hit on a watch is negligable.
- sumtechguy 2y agoIt is not the overhead of the TLS bit but the chain of trust. Putting a caching proxy in the middle of the system is breaking that trust chain. You can do proxy with TLS but it is tricky to do to maintain that chain of trust. A proxy would be a classic way to mitigate (not eliminate) that sort of issue. Either on the serving side or client side. Basically lower the data being returned but not the calls from the clients themselves (this is a DDoS issue). TLS just makes it harder to do proxy.
- ehutch79 2y agoI still have no idea what you're talking about. Cloudflare is either passing traffic through without touching it, or as a proxy is doing tls termination, as they're a trusted CA in most devices/browsers/OSs/etc. None of this really has anything to do with that's happening with OP.