Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] DDOS, open resolvers, how to solve?

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] DDOS, open resolvers, how to solve?


Chronological Thread 
  • From: "A.J. Maurin" <coyo AT darkdna.net>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] DDOS, open resolvers, how to solve?
  • Date: Tue, 29 Oct 2013 17:51:04 -0600

I vote in favor of this. It's reasonable to expect us users to make accounts and login somehow, rather than expose opennic to this abuse.

Julian DeMarchi wrote:
I think the time has come for OpenNIC to no longer have open resolvers
and move to a subscription based service.

Thoughts, ideas?
Why not use an PTPP VPN, where the resolvers only resolve for VPN addresses? For those that want plug-and-play, you can use physical or virtual OpenWRT, DD-WRT or Tomato routers which handle the VPN.

Basically, if any of the VPN users misbehave, send em an email, and if there's no response, kick em off.

If the resolvers are exposed only with a VPN, where only VPN addresses are whitelisted, the VPN can handle authentication and recordkeeping.



Archive powered by MHonArc 2.6.19.

Top of Page