this post was submitted on 27 Jul 2026
260 points (99.2% liked)
/0
2204 readers
544 users here now
Meta community. Discuss about this lemmy instance or lemmy in general.
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
The problem is that this is a client side javascript-based attack - meaning your browser sends these malicious requests. So a DDOS, not "just" a regular (centralized) DOS. Anyone opening the page with javascript turned on (which is 99% of real users, however for Lemmy the statistic's surely a bit better) is an "attacker".
You can - once you know of the nature of the attack (this one's relatively simplistic), just react to any realistic-looking request and ~~block~~ ignore the malicious ones - in this case garbled rng output.
Rate limiting would only lead to what the attacker wants - legit users (who are unknowingly sending these malicious requests) being blocked from accessing the site.