From: H. Peter Anvin Date: Wed, 19 Oct 2005 20:55:35 GMT Subject: Re: The git protocol and DoS Message-ID: <4356B2C7.601@zytor.com> In-Reply-To: <7vmzl544f3.fsf@assigned-by-dhcp.cox.net> Junio C Hamano wrote: > "H. Peter Anvin" writes: > >>It would, however, require a protocol change; I would like to hear what >>people think about this at this stac=ge. > > Well, it is full two days since a majorly visible git protocol > enabled server has been announced, and you probably know what > kind of hits you are getting (and please let us know if you have > numbers, I am curious). About 350 hits so far, total. Utter peanuts. > If we do a protocol change, earlier the > better. You already said that the kernel.org git is > experimental. Does anybody run git daemons and rely on the > current protocol? > > I suspect it would not make *any* sense to have a backward > compatible server that optionally allows this cookie exchange -- > attackers can just say "I am an older client". OTOH, it > probably makes sense to have an option on the client side to > skip the cookie exchange stage. I do not think autodetecting > new/old server on the client side in connect.c is possible. > You mean an option on the *server* to skip the cookie exchange? If so, how would you expect the client to handle it? -hpa