Bartalog / cool-maze

A quick mobile-to-desktop share capability, through matrix barcode
Apache License 2.0
2 stars 6 forks source link

Block brute force attackers #73

Open Deleplace opened 8 years ago

Deleplace commented 8 years ago

E.g. add their IP to an internal list of undesirables. Or accept messages only from registered device IDs, and ban abusive devices.

Deleplace commented 8 years ago

This is the logical consequence of issue #15 [Detect brute force attacks]

Deleplace commented 8 years ago

The potential brute force attack of "listen to many Pusher channels" is already improbable thans to #54.

There is stil however the potential brute force attack of "Sending spam to many target IDs". #35 would slightly mitigate it.

Deleplace commented 8 years ago

Another way blocking criterion is #77 [Reject action if more than 1 listener on channel]

Deleplace commented 8 years ago

Since #108 we estimate that attacks by brute force guessing has low probability, so we say the riposte for these supposedly unlikely events is not current priority.