3 ms·
Why and how do you block application layer stuff like quic?
by cced 3y ago
Why and how do you block application layer stuff like quic?
- jjoonathan 3y agoTiny network tyrants gotta flex somehow.
- spacebacon 3y agoSure, large network tyrants really don’t like the tiny network tyrants that prefer their network traffic to be fully visible.
- spacebacon 3y agoWhen UDM shows you QUIC eats up the majority of your bandwidth you may decide to click to add a rule to block it. You may see a large reduction in overall daily bandwidth as a result. If you watch YouTube you are using QUIC. Certain QUIC vulnerabilities are a 3 or 4 packet compromise.
- cced 3y agoI’m Guessing the sites will then fallback to another protocol correct?
- spacebacon 3y agoYes plain UDP or TCP.
- srj 3y agoYoutube will fall back to TCP. If the bandwidth utilization actually did drop it's probably because the stream quality throttled down. What do you mean by "QUIC vulnerabilities are a 3 or 4 packet compromise"?
- spacebacon 3y agoCVE-2023-39322 for example QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. I like Google Dart and other Google products but I see too many potential issues with QUIC. From my personal experience it has behaved suspiciously on my network.
- srj 3y agoThis is a particular implementation of the QUIC protocol (which is now fixed). Do you think there haven't been vulnerabilities against TCP? Certainly TCP is battle-hardened, but QUIC will get there too.
- spacebacon 3y agoI believe in you. More of you should split off though and create more healthy competition. A 10 to 20 year plan is needed for a new protocol.