From: Junio C Hamano Date: Wed, 19 Oct 2005 20:50:40 GMT Subject: Re: The git protocol and DoS Message-ID: <7vmzl544f3.fsf@assigned-by-dhcp.cox.net> In-Reply-To: <4356A5C5.5080905@zytor.com> "H. Peter Anvin" writes: > It would, however, require a protocol change; I would like to hear what > people think about this at this stac=ge. Well, it is full two days since a majorly visible git protocol enabled server has been announced, and you probably know what kind of hits you are getting (and please let us know if you have numbers, I am curious). If we do a protocol change, earlier the better. You already said that the kernel.org git is experimental. Does anybody run git daemons and rely on the current protocol? I suspect it would not make *any* sense to have a backward compatible server that optionally allows this cookie exchange -- attackers can just say "I am an older client". OTOH, it probably makes sense to have an option on the client side to skip the cookie exchange stage. I do not think autodetecting new/old server on the client side in connect.c is possible.