Re: The git protocol and DoS
- From
- H. Peter Anvin <hpa@zytor.com>
- Date
- Oct 19, 2005, 20:55 UTC
- Message-ID
- <4356B2C7.601@zytor.com>
- In-Reply-To
- <7vmzl544f3.fsf@assigned-by-dhcp.cox.net>
Junio C Hamano wrote:
Show 9 quoted lines
> "H. Peter Anvin" <hpa@zytor.com> writes: > >>It would, however, require a protocol change; I would like to hear what >>people think about this at this stac=ge. > > Well, it is full two days since a majorly visible git protocol > enabled server has been announced, and you probably know what > kind of hits you are getting (and please let us know if you have > numbers, I am curious).
About 350 hits so far, total. Utter peanuts.
> If we do a protocol change, earlier the > better. You already said that the kernel.org git is > experimental. Does anybody run git daemons and rely on the > current protocol?
>
Show 7 quoted lines
> I suspect it would not make *any* sense to have a backward > compatible server that optionally allows this cookie exchange -- > attackers can just say "I am an older client". OTOH, it > probably makes sense to have an option on the client side to > skip the cookie exchange stage. I do not think autodetecting > new/old server on the client side in connect.c is possible. >
You mean an option on the *server* to skip the cookie exchange? If so, how would you expect the client to handle it?
-hpa