my minecraft mod shipped telemetry to a webhook with no limits on it
cybersecurity · Oct 4, 2026 · 2 min read
i wrote a minecraft mod in java. a small quality-of-life thing, the kind of project you start on a weekend because you want a slightly better night-vision toggle. and somewhere in the middle of it i decided it would be interesting to know how many people were actually using it.
so i added telemetry. anonymous, aggregate, harmless. the mod posted a small json payload to a webhook every so often.
here is what i did not add:
- a rate limit on the receiving end
- a consent switch anyone could turn off
- authentication of any kind
- any reasoning at all about the fact that a url inside a client is a url everybody can read
what actually happened
the mod's source is public, so the endpoint was public. within days the channel was not receiving telemetry anymore, it was receiving the same line thousands of times: one real user, then a script, then a script with a loop, then two scripts with a loop.
the payload was worthless but the volume was not. and the failure mode was the embarrassing one: i could no longer tell my own users apart from the abuse, because i had built something where those two things looked identical from the receiving side.
why the data being harmless was not a defence
this is the part i keep coming back to. the payload contained nothing. a script does not care. the only property that made my endpoint dangerous was that it accepted anything from anyone, as fast as the network could deliver.
saying "it is only telemetry" is not a security argument. it is a description of what the attacker does not care about.
the fix
i did not patch the mod and hope nobody looked again. i put a filter in front of the endpoint, at the edge, in cloudflare, so that the requests are rejected before they ever reach anything i own. the edge is the only place that can say no to traffic it did not let me invite in the first place.
it is one rule, and it is the smallest and best piece of security work i have ever done.
what i took from it
- an endpoint is public the moment you ship it, no matter who you meant it for
- limits belong at the edge, not in the client that asked for them
- if you cannot tell a user from an attack, you do not have telemetry, you have a firehose
- deleting something is a valid security control, and it should have been my first option instead of my last
the mod is still out there. the telemetry is not.