• unwarlikeExtortion@lemmy.ml
    link
    fedilink
    arrow-up
    8
    ·
    edit-2
    14 hours ago

    The problem is that this is a client side javascript-based attack - meaning your browser sends these malicious requests. So a DDOS, not “just” a regular (centralized) DOS. Anyone opening the page with javascript turned on (which is 99% of real users, however for Lemmy the statistic’s surely a bit better) is an “attacker”.

    You can - once you know of the nature of the attack (this one’s relatively simplistic), just react to any realistic-looking request and block ignore the malicious ones - in this case garbled rng output.

    Rate limiting would only lead to what the attacker wants - legit users (who are unknowingly sending these malicious requests) being blocked from accessing the site.