3 ms·
I disagree. What you do (well, and what I do in my code) is this: You cache the original IP packets containing the Client Hello. You inspect those packets. And
by Fischgericht 23d ago
I disagree. What you do (well, and what I do in my code) is this: You cache the original IP packets containing the Client Hello. You inspect those packets. And you make your DDoS protection etc based on this. And if you decide the packet is OK forwarding, only then you replay the original IP packets to the destination.
I know that you can not inspect content this way. But there simply are situations where content SHOULD NOT be inspected.
- ranger_danger 22d agoI certainly would not call that adequate, especially for someone like Cloudflare with their scale, and with what their customers expect. What you describe may be technically possible in a very narrow sense, for only specific types of DDoS attacks, but I don't see it being practical in most cases, plus I think ECH would make this difficult to do properly.