Re: const time authentication in bozohttpd

Michael Richardson <[email protected]>
Newsgroups gmane.os.netbsd.devel.security,gmane.os.netbsd.devel.userlevel
Message-ID <[email protected]>
Terry Moore <[email protected]> wrote:
    >> Thank you for your continued explanation and patience.

    > Thank you in turn for getting me to clarify my thoughts.  (It's an
    > interesting question -- how best to discourage these kinds of attacks.)

I'm a little surprised at the techniques.

I'd think that the right answer is, whenever it fails for any reason
at all, that it should perform sleep(base+rand()) before answering.  One
could even time all of the various failures and adjust base to be the
average time it has failed, if one had a stable place outside of a single
process to store the running average.

It seems that the mechanisms used simply penalize legitimate users
with code that isn't optimized well.

--
]               Never tell me the odds!                 | ipv6 mesh networks [
]   Michael Richardson, Sandelman Software Works        | network architect  [
]     [email protected]  http://www.sandelman.ca/        |   ruby on rails    [
signature.asc (application/pgp-signature, 481 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQEVAwUBU62sJoCLcPvd0N1lAQIEqwf8CS5lLYyV8JSHHK18+9gfWc9YMnBVq/cq
P/9qJfjIbBMLTZCPDkSJ49C+InU1Ql5QeeiB2SHHYtpwz3Q5rHMfHM/v4l2iPgrW
ynIxhUMga8Hn83WGVZBy8VqycjF6Cnm1UuT1rgwGhy5pfGQidQswS/Sq8JnlxUr8
KlEiegwaj+rSyPFUOm37pPHHryds0Y8ElkpXulwFdBRA919fVpLZQmTbT/oOFgiz
FvJmm0g1zcFE/315sEn88THe56xM8nLzUg16xQ6IEKU0TWVFrjr8OlFbD+lI1Sj4
aKGhOyXXogpYuXgCyS5Yw4fnjeO3mZgeHJ1DhtzAQLGtnecbH7FyGA==
=Z/zG
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.