Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
udpheaders
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
udpheaders
14y ago
Well, I could prove it to you. Side by side speed test. As for reliability, if you lose access to your "professioinally-configured endpoint" you're SOL. You can't do lookups (assuming you don't know how to do them by hand). Meanwhile I'm
32.
▲
by
udpheaders
14y ago
This is a frustrating problem. Not only with Linux (which I'd argue has some of the best support of any open src OS). The only solution I've come up with is to steer away from hardware that is brand new on the market. Buy stuff that is a
33.
▲
by
udpheaders
14y ago
I did re-read it. But where's the proof they used DNS? Upload a packet capture and let us be the judge.
34.
▲
by
udpheaders
14y ago
Only if it's not already in your cache or in /etc/hosts You can put hosts file on RAM disk. With some servers it's also possible to save and reload caches. Assuming you're not doing hundreds of thousands of new lookups (sites you've never v
35.
▲
by
udpheaders
14y ago
Like when software used to come in a box. That packaging was like some sort of tether to the world of physical goods. You might be going a little strong on the FUD thing though. I think many businesses are tapping into open source and wha
36.
▲
by
udpheaders
14y ago
But I'm not using any of those. (I have used all of them though [OSX, Windows, Linux] so I know what they're like.) Nice try. :) As I said I feel terrible saying this about proprietary software. I've worked for companies that sell commer
37.
▲
by
udpheaders
14y ago
Next week: Economic Growth Doesn't Lead to ________, a New 65-Year Study Finds Fill in the blank. Do people want "economic growth" or whatever that might be assumed to lead to, or do they just not want to donate money to their country throu
38.
▲
by
udpheaders
14y ago
I honestly can't think of one proprietray program I've paid for (and I have bought some expensive software) that exceeds the quality or reliability of the free, open source programs I use. Sometimes I feel like I've been duped by every vend
39.
▲
by
udpheaders
14y ago
Thanks. http://tools.ietf.org/html/rfc4732
40.
▲
by
udpheaders
14y ago
"If builders constructed buildings the way software developers write software, the first woodpecker to come along would cause the collapse of civilzation."
41.
▲
by
udpheaders
14y ago
The real solution is not to use open resolvers and open caches, full stop. Run your own cache on localhost. djb has always advised against third party DNS, but people don't listen. I've even caught the author of the DNS/BIND book admitti
42.
▲
by
udpheaders
14y ago
Yet another reason DNSSEC is more trouble than it's worth. It's a gift to anyone wanting to do this type of DDOS.
43.
▲
by
udpheaders
14y ago
Right. As the top post also points out. There's no way to distinguish incoming UDP traffic as "spoofed". My question is does anyone filter UDP egress based on source IP? Is there guidance somewhere that tells admins to do this? Let me put
44.
▲
by
udpheaders
14y ago
So you are saying it is common practice to block outgoing UDP packets based on source IP? I did not know this. Does your ISP do that? Everyone is expected to block ingress with spoofed IP. But I can't find an BCP for blocking UDP egress
45.
▲
by
udpheaders
14y ago
Re-read the blog post. He's speculating the attack used DNS. (Though he has no proof.) In that case, with UDP, spoofed headers are allowed out. Connectionless. Cloudflare uses anycast DNS - machines in different geographically located da