4 ms·
Should we perhaps have sent the request through anonymized pidgeon? When you send an e-mail to someone you can find out quite a lot of information from headers,
by ahnberg 14y ago
Should we perhaps have sent the request through anonymized pidgeon? When you send an e-mail to someone you can find out quite a lot of information from headers, from a nick or a given name.
When contacting ISPs some people attach contact information so that the ISP can request more information, maybe even make a call to verify identity and discuss the matter to help resolve it.
This doesn't mean that the information is intended for the abuser himself. I'd expect the ISP to send anonymized information/questions to the owner of said service, and not just forward "everything" (especially without discussion with the reporting party).
Reporting DDoS and abusers risks putting a huge target on yourself, your company, your servers, etc.
That is what the issue is about.
- eliasmacpherson 14y agoI specified redacting the details, i.e. the irc nickname. If the information within the headers is that sensitive, the headers should probably not be forwarded from efnet to hetzner. At its most basic their servers are attacking efnets and so should be considered hostile. By all means pass on contact information to resolve amicably - but don't leave sensitive information. There's no reason to pass on irc nicks or sensitive email addresses - what use are they to hetzner? I have the same expectation of efnet as you have for the ISP. If the issue is that efnet is being identified as the reporter to the rogue attacker, then that is not what is stated in the efnet admin's text.
- ahnberg 13y agoEFnet didn't pass anything on. EFnet reported abuse, and the EFnet reporting staff members information was the information that was leaked/forwarded to the abuser. Not a third party to whom EFnet acted proxy. You seem to misunderstand the situation.