I was planning on getting that set up, but people discovered it faster than anticipated :) I’ll do it soon
Not using HTTPS opens up a bunch of new possibilities of how to cheat...
Can you send an http request spoofing the IP address it's from? I bet you could with enough attempts because you only have to successfully guess the TCP syn cookie once...