4 ms·
> block “rogue” (read: tracking) IPs. With IPv6 that's as impractical as blocking "rogue" FQDNs.
by skunkpocalypse 7y ago
> block “rogue” (read: tracking) IPs.
With IPv6 that's as impractical as blocking "rogue" FQDNs.
- tambre 7y agoWhy? Just block ranges.
- strenholme 7y agoExactly. If I were to update this code, for IPv4 blocking, I would allow it to block /32 (single IP) and /24 networks. For IPv6 blocking, I would allow blocking a single IPv6 address, a /64 range, and (for extreme offenders) a /48 range. One way to do this is to have multiple hash tables: One for single IPv4 addresses, one for IPv4 /24 ranges, one for single IPv6 addresses, one for /64 IPv6 ranges, and one for /48 IPv6 ranges. Note that while the hashes have (generally speaking) a “big O” of 1, we need to perform one additional operation per range size. IPv4 /32 and /24 blocking requires two lookups, and IPv6 /128, /64, and /48 blocking requires three lookups.
- skunkpocalypse 7y agoUm, collateral damage? I'm supposed to be penalized for colocating my gear in a data center (i.e. routable prefix) that hosts a tracker? If your scheme were implemented the tracker companies would certainly respond by buying a 1U in every data center they can find and buying one routable IP from every carrier in each facility. They can easily afford this.