Live data from Hacker News

IP Spoofing

idea.popcount.org

1–10 of 136 posts

Re: IP Spoofing

#3
There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not originate from your network. It would make ddosers life harder.

Re: IP Spoofing

#4
post #3

There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…

I suspect there is some excuse.

Re: IP Spoofing

#6
post #3

There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…

>There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce.

With what hardware?

Re: IP Spoofing

#8
Netflow is a great example of the dual use aspects of tech between surveillance and defense. Making Netflow data more widely available looks like it is going to be essential for defending that Internet but at the same time Netflow data can threaten the anonymity of Tor users.[0][1]

[0] https://blog.torproject.org/blog/traffic-correlation-using-n...

[1] https://gitweb.torproject.org/torspec.git/tree/proposals/251...

Re: IP Spoofing

#9
post #6
post #3

There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…

>There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. With what hardware?

If you're a transit provider, peering partner, or are an eyeball or content org with networking gear, this is trivial on your edge gear.

There is no excuse except laziness for not doing do.

https://tools.ietf.org/html/bcp38 (Note: This is from May 2000)

Re: IP Spoofing

#10
post #3

There is no excuse for not securing your network to allow spoofing from it. Most of the big players like leaseweb or ovh do not allow that. But there are some providers that still allow you to spoof source ip address. There should be consensus about droping routes on BGP level to networks that send packets with source ips that they do not announce. It's really simple to drop packets on switches/routers that do not or…

I agree 100%.

I've also wondered why ISPs don't do more to shut down customers that are participating in a DDOS (at least for DDOS attacks where the source IP isn't spoofed)? I would be very happy if my ISP were to let me know that something on my network is involved in an attack.

Post reply on HN