Rate limiting without IP tracking

  • Wrong PINs are counted per case number, under an HMAC of it, so a Redis dump does not list which cases someone tried. After MAX_ACCESS_ATTEMPTS (5) within ACCESS_LOCKOUT_MINUTES (15), the status page asks to wait. A correct PIN always works.
  • Admin passwords are counted per username (MAX_LOGIN_ATTEMPTS) and across all accounts, against password spraying (ADMIN_FAILED_LOGIN_ALERT_THRESHOLD).
  • nginx limits every route, the submission wizard (POST /submit) included: 10 requests/s with a burst of 30 per client address. The counters live in nginx memory only and are never logged. The onion listener has its own shared zone.
  • Helm: the chart sets the same limit on its ingress-nginx Ingress. With another ingress controller, set an equivalent one.

Edit this page on GitHub