Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Throttle IPv6 signup for subnet #17588

Merged
merged 1 commit into from Feb 18, 2022
Merged

Conversation

tribela
Copy link
Contributor

@tribela tribela commented Feb 18, 2022

Currently, Mastodon throttle signup 25/5min per specific IP
Unlike IPv4, IPv6 address is very different. For an example, Cloud VPS providers give entire /64 subnet to a single server.

So this PR raise the bar using 64 bit netmask. while it is narrow enough compare to IPv4(=32bit mask)

@HanbitGaram
Copy link

About 20 minutes ago, a large amount of IPv6 spambots occurred in my instance.
I am in favor of this action.

https://www.abuseipdb.com/user/56635

image

@SuperSandro2000
Copy link
Contributor

Cloud VPS providers give entire /64 subnet to a single server.

Some even /56 but are there smaller ones? If so this could limit people on those.

@Gargron Gargron merged commit 1de2e3f into mastodon:main Feb 18, 2022
@tribela tribela deleted the throttle-ipv6-signup branch February 21, 2022 01:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants