4 ms·
"Anyone with large enough traffic will use some edge network like Cloudflare which would also get a different address depending on your location." What if the
by textmode 8y ago
"Anyone with large enough traffic will use some edge network like Cloudflare which would also get a different address depending on your location."
What if the request is always sent from the same location?
What if when the user moves location, e.g., from one country to another, she updates her stored IP addresses?
"And you can't tell easily which one want."
Personal experience as a user is that when it is an "intended" change, the previous IP address no longer hosts the content.
Personal experience is that this is surprisingly rare.
In the case of the more common load balancing, the user who may store several IP addresses for the website, all of which continue to serve the content. She can choose which of those she prefers.
Personal experience is that this works very well.
Further questions:
If this was a BGP hijack, why did the hijackers target the IP addresses of DNS servers, rather than the target IP addresses of the websites?
If they had targeted the IP addresses of the websites, then what would be the possible mitigations, if any?
- viraptor 8y ago> What if the request is always sent from the same location? Then you may get the same IP. > What if when the user moves location, e.g., from one country to another, she updates her stored IP addresses? It doesn't have to be a different country. Different ISPs with different peering may get different results. Moving between your home wifi and you phone tethering may get different results. So depending on your usage style, it's between "change multiple times a day" and "no change". > Personal experience as a user is that when it is an "intended" change, the previous IP address no longer hosts the content. In some cases I'm sure it's true. In others, it isn't. Basically it's not a reliable indicator. > If this was a BGP hijack, why did the hijackers target the IP addresses of DNS servers, rather than the target IP addresses of the websites? Haven't seen the site's announced block, but it's possible that it's announced as /24 block. This attack was possible because Amazon announced /23 and the attacker could announce something more specific.
- textmode 8y ago"So depending on your usage style, it's between "changes multiple times a day" and "no change"." For me, for each ISP, it's been "no change". Can only relate personal experience.