3 ms·
The problem is that that there are ISP's who are not implementing BCP38 (http://www.bcp38.info http://www.bcp38.info)
by vadiml 10y ago
The problem is that that there are ISP's who are not implementing BCP38 (http://www.bcp38.info http://www.bcp38.info)
- Retr0spectrum 10y agoThis will only take us so far. Many of these botnets are large enough that they don't need any spoofing/amplification to be effective.
- thesehands 10y agowe need customers to want BCP38 implementing routers in their homes
- unethical_ban 10y agoBut... the routers and IoT are the ones often compromised. The ISP needs to enforce it. Also, anyone who understands networking (everyone on HN, for this purpose) should have a default-deny firewall for at least their IoT devices, if not every device on their network.
- pixl97 10y agoHow does that stop spoofing addresses inside the segment? If I am 8.8.8.8 and I fake 8.8.4.4, you still get my traffic, and someone else gets the complaint.
- nordsieck 10y agoIt won't stop spoofing, but if you assume that the botnet hosts are evenly distributed across the address space, you're going to cut the spoofed traffic to 1/(256^2). At that point, you might not even notice the DDOS.
- craigsmansion 10y agoIf you are 8.8.8.8 and you fake 8.8.4.4, it's likely the same person getting the complaint. If you just picked those two addresses at random from the entire range just to serve as an illustration, you should have bought a lottery ticket instead.