3 ms·
Such attacks are possible because ISPs do not want to adopt a protocol that would allow any host to send a special packet to block malicious traffic on the upst
by codedokode 3y ago
Such attacks are possible because ISPs do not want to adopt a protocol that would allow any host to send a special packet to block malicious traffic on the upstream provider or even at the source network. In this case networks like Cloudflare would become unnecessary.
- throwawayqqq11 3y agoISPs could enshitty-sell it though.
- supertrope 3y agoAltruism is not profitable.
- ilyt 3y agoThat costs a lot of money to implement. They are in business of selling pipes, not pipe filters
- Egrodo 3y agoIf it becomes this easy to block traffic couldn't malicious applications really mess up a user by spamming out reject packets for common IP?
- deleted 3y ago[deleted]
- Ajedi32 3y agoI think it would have to be something like "Block traffic from <offending IP> intended for <my IP>. <TTL>. <Cryptographic signature verifying that I control my IP>."
- codedokode 3y agoThe intermediate routers can send back a confirmation code, and you must send a new reject packet with this code to confirm the ban.
- DanAtC 3y agoThe tier 1 & 2 ISPs I've worked with have a blackhole BGP community. https://www.rfc-editor.org/rfc/rfc7999.html https://www.rfc-editor.org/rfc/rfc7999.html
- codedokode 3y agoAs I understand, "blackholing" is basically siding with criminals: attackers want the victim to get off the network, and by "blackholing" the network operator complies with their demand, which allows attackers to save resources. Everybody wins except for the victim.
- averageRoyalty 3y agoImplementation dependent. Normally for DDoS migitation, you blackhole on your normal ISP, and you simultaniously advertise on the mitigator. The mitigator scrubs the traffic and sends the clean stuff over a private session back to you. If you just black hole and move on, yes that's a lose. However many ISPs will, because the quick reaction holds the most value for them.