4 ms·
You can only block access to your IP address, so you can ban someone from sending packets to you but not to anyone else. My proposal is well-thought and doesn't
by codedokode 3y ago
You can only block access to your IP address, so you can ban someone from sending packets to you but not to anyone else. My proposal is well-thought and doesn't require any lists like Spamhaus that have vague policies for inclusion and charge money for removing. My proposal doesn't have any potential for misuse.
- ComodoHacker 3y agoHow can it protect from... botnets, where there are tens of thousands "someones"?
- codedokode 3y agoYou can only ban packets coming to your IP. Botnet can only ban packets coming to its IP addresses.
- plagiarist 3y agoSorry, this is not well-thought and certainly has potential for abuse. This is on IP and not domain? What is the signing authority and cryptography mechanism preventing a spoofed request?
- codedokode 3y agoWhen you send a "reject" packet, the imtermediate routers send back a confirmation code. You must send this code back to them to confirm that "reject" packet comes from your IP address. No cryptography or signing required.
- plagiarist 3y agoI don't think you understand how networking operates at a packet level.
- tsimionescu 3y agoIt's not very hard to send packets with a fake source IP, especially if you don't care about the reply.
- ndriscoll 3y agoSeems easy enough to require (i.e. regulate) end-customer ISPs to drop any traffic with a source IP that isn't assigned to the modem it's coming from. This would at least prevent spoofing from e.g. compromised residential IoT devices. Are they not already doing that filtering? Is there any legitimate use-case to allow that kind of traffic?
- gene91 3y agoSomeone has to go and add the filtering. Nowadays (or maybe since ten years ago) most ISPs have the filter, but not the last 1% (or maybe 0.01%).
- codedokode 3y agoThe routers can send back a confirmation token to confirm the origin address.
- tsimionescu 3y agoFirst of all, there is no way this works reliably for anything but the first hop. There is no way for a router to send a packet to you in a way where you can reply to that router unless you are connected directly to it, unless all ISP routers start being assigned public IP addresses. Additionally, there are normally many paths between you and your attacker, and there is no guarantee that packets you send will take the same path as the packets you were receiving. Especially as the routing rules get modified by your successful blocking requests. That also means that every router now has to maintain a connection table to keep track of all of the pending confirmations, and to periodically check that table for expirations so it can clean it up. Maybe not that bad for a local router, but this is completely unworkable for routers handling larger parts of the internet. And of course, anyone who has a tap into that level can trivially spoof all of the correct replies so it's still not a secure mechanism.