2 ms·
In a world of virtualized services, blocking IP or MAC will also only get you so far. It's fairly easy to switch servers onto a different IP address, a differe
by incomethax 15y ago
In a world of virtualized services, blocking IP or MAC will also only get you so far. It's fairly easy to switch servers onto a different IP address, a different MAC address by simply using a different machine or configuration.
DNS is the most vulnerable part of the stack simply because its the one thing in the stack that is centralized (loosely speaking).
- Luyt 15y agoIs it really that easy? Both my home ADSL as my datacenter servers have permanent IP adresses, which I can't change. I could change the MAC of the network interfaces, but not the IP address. Or do you mean going through a VPN of some kind?
- lsc 15y ago>Or do you mean going through a VPN of some kind? the VPN of some kind is the easy way to do it, yes. Setting up a new VPN provider is pretty trivial. I could do so tomorrow; all I'd need is one of those visa prepaid cards to do so anonymously. But the point is that yeah, sure, the government could mandate that we block certain IPs but it would be difficult for the government to do and fairly easy for targets to get around - going after the centralized naming resources is going to be much easier, and is going to produce much less resistance. It's true that there have been alternate dns root servers for some time now; it's not a technically difficult thing to set up. But it is a huge problem of trust. It's very difficult to design a system that is resistant to governmental pressure but is still trustworthy enough that when I type in a site name I can be fairly certain I'm getting the IP address for that site and not a pretender.