Skip to content
This repository has been archived by the owner on Apr 26, 2024. It is now read-only.

repeatedly calling /_matrix/client/r0/keys/upload DoSes federation #3657

Open
richvdh opened this issue Aug 6, 2018 · 1 comment
Open

repeatedly calling /_matrix/client/r0/keys/upload DoSes federation #3657

richvdh opened this issue Aug 6, 2018 · 1 comment
Labels
A-Device-List-Tracking Telling clients about other devices. Often related to E2EE. P4 (OBSOLETE: use S- labels.) Okay backlog: will not schedule, will accept patches S-Minor Blocks non-critical functionality, workarounds exist. Security T-Defect Bugs, crashes, hangs, security vulnerabilities, or other reported issues.

Comments

@richvdh
Copy link
Member

richvdh commented Aug 6, 2018

A client seemed to be uploading new device keys several times a second; this led to a big backlog of stuff to send over federation, and the federation sender got behind

@neilisfragile neilisfragile added security z-p2 (Deprecated Label) labels Aug 28, 2018
@DMRobertson DMRobertson added P4 (OBSOLETE: use S- labels.) Okay backlog: will not schedule, will accept patches S-Minor Blocks non-critical functionality, workarounds exist. T-Defect Bugs, crashes, hangs, security vulnerabilities, or other reported issues. A-Device-List-Tracking Telling clients about other devices. Often related to E2EE. and removed z-p2 (Deprecated Label) labels Jan 27, 2022
@DMRobertson
Copy link
Contributor

Maybe worth rate limiting the endpoint to upload device keys?

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
A-Device-List-Tracking Telling clients about other devices. Often related to E2EE. P4 (OBSOLETE: use S- labels.) Okay backlog: will not schedule, will accept patches S-Minor Blocks non-critical functionality, workarounds exist. Security T-Defect Bugs, crashes, hangs, security vulnerabilities, or other reported issues.
Projects
None yet
Development

No branches or pull requests

4 participants