Hi,

I wonder what are suitable methods to protect a Lemmy instance against DDOS attacks.

For example, can we use Cloudflare? Or it could break the federation?

Any ideas/suggestions?

@pinknoise@lemmy.ml
link
fedilink
2
edit-2
3Y

Websites usually use transport encryption but the password itself isn’t encrypted. There are authentication schemes that won’t send plaintext passwords (by involving some kind of challenge) but they won’t work without javascript (except http digest access authentication but thats no good) and you shouldn’t ask web-developers to implement them since they will find a way to fuck it up.

Lemmy Administration
!lemmy_admin@lemmy.ml
Create a post

Anything about running your own Lemmy instance. Including how to install it, maintain and customise it.

Be sure to check out the docs: https://dev.lemmy.ml/docs/administration.html

If you have any problems, describe them here and we will try to help you fixing them.

  • 1 user online
  • 1 user / day
  • 1 user / week
  • 1 user / month
  • 1 user / 6 months
  • 1 subscriber
  • 8 Posts
  • 4 Comments
  • Modlog