pull down to refresh

I think that you ought to put the clanker on the analysis side, but on the live path I'd do it the same way as you'd configure a WAF: close everything then enable by narrow exception. Then you monitor mostly where you're too strict.

128 sats \ 1 reply \ @justin_shocknet 21 Sep -210 sats

The whitelist-only approach is definitely necessary in some environments, but I think at odds with the use of most Lightning nodes since its value is in openness. Strike and I believe CashApp did and may still do whitelist-only peers, but also somewhat unique cases being exchanges.

I know others have used proxy nodes, where their main node only peers with other edge nodes they operate.

Clankers definitely make it easier to build a whitelist, but what's whitelisted today in an open network may still need to be blacklisted tomorrow if someone finds a new exploit.