TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Excessive load on NTP servers

354 点作者 BCM43超过 8 年前

15 条评论

easytiger超过 8 年前
Wait.. they are saying the app itself is making NTP requests?<p>&gt; <i>Confirmed - starting up the iOS Snapchat app does a lookup to the domains you listed, and then sends NTP to every unique IP. Around 35-60 different IPs.</i><p>Hmm. Is that a fraud prevention thing or something? No way on earth a user app should be getting its own time
评论 #13220909 未加载
评论 #13220088 未加载
评论 #13220912 未加载
评论 #13224275 未加载
评论 #13219992 未加载
评论 #13227398 未加载
sschueller超过 8 年前
Why on earth would you do that?<p>If you want to prevent users from altering their time use your server and do a time compare with your server.<p>NTP can be easily intercepted and altered so it would make a lot more sense to do this via a encrypted certificate pinned communication path increasing my work load drastically to alter the time.<p>I snapchat going to pay for the DDOS they created?
评论 #13221240 未加载
评论 #13220910 未加载
Declanomous超过 8 年前
For whatever reason, ntppool.org is blocked at my work.<p>And of course, you don&#x27;t get the page that states why when the website is served via https. Not that I need to see the page to know it was either blocked for &quot;hacking&quot; or &quot;entertainment&quot;, and I&#x27;m guessing it&#x27;s not entertainment.<p>Edit: This probably explains why our clocks have been off by 45 minutes since Monday. I guess it will be entertaining to see how long it takes for IT to figure this one out.
评论 #13220271 未加载
评论 #13220631 未加载
评论 #13222017 未加载
评论 #13220186 未加载
acqq超过 8 年前
According to the forum, the pattern matched this third-party library:<p><a href="https:&#x2F;&#x2F;github.com&#x2F;jbenet&#x2F;ios-ntp" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;jbenet&#x2F;ios-ntp</a><p>Specifically, all the servers(!) from here are contacted: <a href="https:&#x2F;&#x2F;github.com&#x2F;jbenet&#x2F;ios-ntp&#x2F;blob&#x2F;master&#x2F;ios-ntp-lib&#x2F;NetworkClock.m#L121" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;jbenet&#x2F;ios-ntp&#x2F;blob&#x2F;master&#x2F;ios-ntp-lib&#x2F;Ne...</a><p>Note that the library author wrote:<p>&quot;ios-ntp is often (mostly?) used to make sure someone hasn&#x27;t fiddled with the system clock. The complications involved in using multiple servers and averaging time offsets is overkill for this purpose. The following skeleton code is all that is needed to check the time.&quot;<p>And that &quot;skeleton&quot; contacts just &quot;time.apple.com&quot;<p>But the library really has the default possibility of contacting a lot of the ntp.org servers from a big list (&quot;createAssociations&quot; with no parameters!) and it&#x27;s bad.<p>As we know, the developers like to just &quot;copy-paste&quot; whatever is where. Or use any defaults. &quot;Hey it works.&quot;
评论 #13220202 未加载
评论 #13220356 未加载
评论 #13222238 未加载
coleca超过 8 年前
FWIW my teenage daughter has been complaining about this latest Snapchat update for iOS the past couple days. It constantly crashes and causes the phone to reboot itself. Looking at Twitter, there&#x27;s tons and tons of people reporting the same issue, so it seems pretty widespread. Wonder if it&#x27;s related to this NTP issue.
评论 #13220430 未加载
sateesh超过 8 年前
It is interesting to read through the whole thread in a chronological order starting from the first message: <a href="http:&#x2F;&#x2F;mailman.nanog.org&#x2F;pipermail&#x2F;nanog&#x2F;2016-December&#x2F;089525.html" rel="nofollow">http:&#x2F;&#x2F;mailman.nanog.org&#x2F;pipermail&#x2F;nanog&#x2F;2016-December&#x2F;08952...</a><p>It took 4 days, to zero on the root cause. As is usual in a complex scenario like this there are a few false positives, some suspects abusing the protocol and alas final redemption. Amazing work by a dedicated group of technical folks in coordinating (just via emails, I suppose) and tracing the root cause.
lima超过 8 年前
Worst part is that they did not bother to use a vendor zone.
评论 #13220142 未加载
mark-r超过 8 年前
This happens often enough that Wikipedia has a page devoted to it: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;NTP_server_misuse_and_abuse" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;NTP_server_misuse_and_abuse</a><p>The first one I had heard of was Netgear vs. UW-Madison.
gbrown_超过 8 年前
For all of Apple&#x27;s App Store vetting one would think this kind of behavior would have thrown up a flag at some point no?
评论 #13220043 未加载
评论 #13220215 未加载
评论 #13220140 未加载
_RPM超过 8 年前
And to think that SC&#x27;s engineering is praised among college kids is laughable.
评论 #13225114 未加载
Faaak超过 8 年前
I wondered why I was seeing so much packet loss on my IP: <a href="http:&#x2F;&#x2F;mrtg.vi-di.fr&#x2F;krootservers.ping.html" rel="nofollow">http:&#x2F;&#x2F;mrtg.vi-di.fr&#x2F;krootservers.ping.html</a><p>Guess I know why now..
thejosh超过 8 年前
Yeah, it&#x27;s been really hit and miss here in AU for a few people I know.
sstevo66超过 8 年前
I do some work for the Network Time Foundation and we were not contacted by snapchat as far as I know. Anyone have a contact there, they probably need our help.
评论 #13241615 未加载
1_2__3超过 8 年前
I for one am shocked - shocked! - that Snapchat would be the kind of company to be cavalier about this kind of thing.
known超过 8 年前
Captcha should fix it