Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] DDOS, open resolvers, how to solve?

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] DDOS, open resolvers, how to solve?


Chronological Thread 
  • From: Quinn Wood <wood.quinn.s AT gmail.com>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] DDOS, open resolvers, how to solve?
  • Date: Thu, 12 Dec 2013 20:34:13 -0600

On Thu, Dec 12, 2013 at 8:26 PM, Guillaume Parent <gparent AT gparent.org> wrote:
> Incoming packets will not be stopped by a silly HTML form unless every
> upstream ISP we have cooperates with us, and those packets* are a
> significant threat for people with low transfer connections.
>
I think the privacy issue has been solved- since only the user can
ever see which IPs are tied to their account. Unless there's something
I missed.

As for stopping incoming traffic, sure incoming traffic can't be dealt
with using this system. But outgoing traffic can, using any type of
acl including this one.

I agree that OpenNIC should not make it policy. It should be up to
individual nameserver operators to implement or ignore this type of
global whitelist. What choice an operator has made should obviously be
clear to avoid confusion to the user. If a user wants an account and
wishes to put no IPs in it (only use it for mailing lists for example)
they shouldn't notice any difference compared to a user with IPs in
their list.



Archive powered by MHonArc 2.6.19.

Top of Page