4 ms·
I feel confident that no system exposed to the internet should have a problem with 50,000 requests per month! If they do, they probably shouldn't run a public N
by iancarroll 20d ago
I feel confident that no system exposed to the internet should have a problem with 50,000 requests per month! If they do, they probably shouldn't run a public NTP server, or have a public IP address at all.
- saghm 20d agoOkay, so you're just confident in exactly how many requests everyone else in the world will be making if you try to pentest resources unbeknownst to their owners.
- iancarroll 20d agoAre you confident you are not viewing too many pages on HN? What if many other people are also trying to read this thread? I think this line of reasoning doesn't make any sense. The internet is not an inherently safe network regardless of what we wish for; we can't wish away the bad activity, and it's only going to increase. The activity that helps prevent the bad activity from working is a net positive.
- saghm 20d ago> Are you confident you are not viewing too many pages on HN? What if many other people are also trying to read this thread? I think it's pretty disingenuous to compare viewing a couple of pages once a day with running scripting tools against over 400 websites. > I think this line of reasoning doesn't make any sense. The internet is not an inherently safe network regardless of what we wish for; we can't wish away the bad activity, and it's only going to increase. The activity that helps prevent the bad activity from working is a net positive. Oh good, no one has ever claimed "it's for your own good" when doing something selfish without consent.
- iancarroll 20d agoWe can quantify the impact of the scripting tools pretty easily - 1.5k requests per day! I just went on Reddit and viewed a few posts, and it caused about 500 HTTP requests in DevTools. Luckily HN is not that bloated, but I just don't see the number of requests as meaningful even if it was orders of magnitude higher. As the OP said, they don't do anything when the server isn't vulnerable, and serving a 404 page is incredibly cheap.