• naught@sh.itjust.works
    link
    fedilink
    arrow-up
    9
    ·
    19 hours ago

    They can block requests from a specific origin or implement tailored rate limiting rules or disable CORS from that instance. Probably more too

    • unwarlikeExtortion@lemmy.ml
      link
      fedilink
      arrow-up
      8
      ·
      edit-2
      14 hours ago

      The problem is that this is a client side javascript-based attack - meaning your browser sends these malicious requests. So a DDOS, not “just” a regular (centralized) DOS. Anyone opening the page with javascript turned on (which is 99% of real users, however for Lemmy the statistic’s surely a bit better) is an “attacker”.

      You can - once you know of the nature of the attack (this one’s relatively simplistic), just react to any realistic-looking request and block ignore the malicious ones - in this case garbled rng output.

      Rate limiting would only lead to what the attacker wants - legit users (who are unknowingly sending these malicious requests) being blocked from accessing the site.