Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Add Expiring Token to Endpoint for DDOS Protection #39

Closed
dshanske opened this issue Nov 30, 2014 · 3 comments
Closed

Add Expiring Token to Endpoint for DDOS Protection #39

dshanske opened this issue Nov 30, 2014 · 3 comments

Comments

@dshanske
Copy link
Collaborator

Add an expiring, random or encrypted token to webmention endpoints, preventing the accumulation of lists of endpoints and forcing attackers to look up the webmention endpoint of each of the sites they want to use to DDOS a victim.

http://indiewebcamp.com/DDOS#Expiring_token_in_endpoint

@peterwilsoncc
Copy link

FWIW, WordPress has built in nonce functionality.

@peterwilsoncc
Copy link

I'm not ready for a pull request but I've started working on this in /peterwilsoncc/wordpress-webmention/tree/issue39

I'm dogfooding it on my own site and will see how it goes.

@pfefferle
Copy link
Owner

see: #41

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants