Re: const time authentication in bozohttpd
Michael Richardson <[email protected]>
| Newsgroups | gmane.os.netbsd.devel.security,gmane.os.netbsd.devel.userlevel |
|---|---|
| Message-ID | <[email protected]> |
Terry Moore <[email protected]> wrote: >> Thank you for your continued explanation and patience. > Thank you in turn for getting me to clarify my thoughts. (It's an > interesting question -- how best to discourage these kinds of attacks.) I'm a little surprised at the techniques. I'd think that the right answer is, whenever it fails for any reason at all, that it should perform sleep(base+rand()) before answering. One could even time all of the various failures and adjust base to be the average time it has failed, if one had a stable place outside of a single process to store the running average. It seems that the mechanisms used simply penalize legitimate users with code that isn't optimized well. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works | network architect [ ] [email protected] http://www.sandelman.ca/ | ruby on rails [
signature.asc
(application/pgp-signature, 481 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEVAwUBU62sJoCLcPvd0N1lAQIEqwf8CS5lLYyV8JSHHK18+9gfWc9YMnBVq/cq P/9qJfjIbBMLTZCPDkSJ49C+InU1Ql5QeeiB2SHHYtpwz3Q5rHMfHM/v4l2iPgrW ynIxhUMga8Hn83WGVZBy8VqycjF6Cnm1UuT1rgwGhy5pfGQidQswS/Sq8JnlxUr8 KlEiegwaj+rSyPFUOm37pPHHryds0Y8ElkpXulwFdBRA919fVpLZQmTbT/oOFgiz FvJmm0g1zcFE/315sEn88THe56xM8nLzUg16xQ6IEKU0TWVFrjr8OlFbD+lI1Sj4 aKGhOyXXogpYuXgCyS5Yw4fnjeO3mZgeHJ1DhtzAQLGtnecbH7FyGA== =Z/zG -----END PGP SIGNATURE-----