Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I suspect bog-standard per-IP rate limiting would also mitigate this, no?


People report that the requests come from many thousands of IPs

Any firewall worth its salt (like PF) can measure which IPs are making more requests per minute than is reasonable and shove them into a list to be handled separately (whether by blocking them outright or by putting them in a slower / lower-priority queue). Putting all those thousands of IPs into a queue that only gets 1% of the available bandwidth would solve the issue quite nicely, I think.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: