Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Possibile DoS (?) #313

Closed
dtonon opened this issue Jun 28, 2024 · 3 comments
Closed

Possibile DoS (?) #313

dtonon opened this issue Jun 28, 2024 · 3 comments

Comments

@dtonon
Copy link

dtonon commented Jun 28, 2024

I'm testing the onboarding and the general UX and I spotted a possible problem: when the user take a position he is asked to pay a LN invoice in 15 minutes; during this time frame the position is locked and hidden, and it is not available to any other user. I suppose it's quite trivial to create a bot that randomly generates new key-pairs and take all the positions, ruining the operability of the service.
Maybe a solution could be to wait the LN payment to lock the position, or to require non-trivial PoW when signing the take event.

@grunch
Copy link
Member

grunch commented Jun 28, 2024

The PoW solution sounds good, it's easy to implement and it can be a pain for spamming bots

@arkanoider
Copy link
Collaborator

check #341

@Catrya
Copy link
Collaborator

Catrya commented Aug 9, 2024

Closed via #341

@Catrya Catrya closed this as completed Aug 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants