3 ms·
Egress filtering is not a solution. I've had attacks come from Asia and Russia and none of the hosts respond. I've also tried contacting their upstream provide
by codexon 14y ago
Egress filtering is not a solution.
I've had attacks come from Asia and Russia and none of the hosts respond. I've also tried contacting their upstream providers.
The DNS system needs to be changed.
- spoiler 14y agoThe DNS system needs to be changed. It needs to change, but I highly doubt it will for at least a few decades. Too many things rely on it, and it would require way too many resources and a miserably long time to change everything to the new thing.
- Daniel_Newby 14y agoEgress filtering would happen within a few days if someone DDoSed every open resolver with other open resolvers. In fact, saturation of the outbound links would effectively be egress filtering.
- jessaustin 14y agoHaha this would be kind of awesome. Obviously this would be bad news for the open resolvers' home networks, but could their upstreams handle it (i.e. maybe they would have to drop resolver traffic but not anything else)? If so maybe this Cloudflare should prepare such a response for the next time someone pulls this.