top | item 46280810

(no title)

murderfs | 2 months ago

Ratelimiting doesn't solve anything, you can just parallelize your queries across IP addresses.

discuss

order

overfeed|2 months ago

The whole "defense in depth" principle disagrees. Having a layered defense can not only buy defenders time, but downgrades attacks from 100% data exfiltration to <10%

arcfour|2 months ago

Increasing the barrier to entry from "trivial" to "less trivial" is always a good start.

pragma_x|2 months ago

Yup. This is some of the stuff that gets missed when understanding Security.

Ultimately, you're just buying time, generating tamper evidence in the moment, and putting a price-tag on what it takes to break in. There's no "perfectly secure", only "good enough" to the tune of "too much trouble to bother for X payout."