Skip to content

Add Expiring Token to Endpoint for DDOS Protection #39

Closed
@dshanske

Description

@dshanske

Add an expiring, random or encrypted token to webmention endpoints, preventing the accumulation of lists of endpoints and forcing attackers to look up the webmention endpoint of each of the sites they want to use to DDOS a victim.

http://indiewebcamp.com/DDOS#Expiring_token_in_endpoint

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions