Re: The git protocol and DoS

From: H. Peter Anvin <hpa@zytor.com>
Date: 2005-10-20 08:01:19
Junio C Hamano wrote:
> Linus Torvalds <torvalds@osdl.org> writes:
> 
>>But once you're talking to a git-aware 
>>SYN-flooder, I don't think a challenge-response makes it any better, since 
>>a git-aware SYN-flooder would just be written to give the right response.
> 
> I think Peter's point is that the one that can give the right
> response needs to read from the server to compute it, and at
> that point it is not a "SYN-flooder" anymore.
> 

Right.  It has been shown that requiring some effort on the part of the 
client before the server spends work on it can greatly reduce the 
capabilities of a limited-resource client to execute a DoS.

	-hpa
-
To unsubscribe from this list: send the line "unsubscribe git" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Received on Thu Oct 20 08:02:29 2005

This archive was generated by hypermail 2.1.8 : 2005-10-20 08:02:33 EST