Warning: Sales pitch masquerading as a technical talk.
Warning: Someone's cranky. It's a technical talk. It's much better to hear from people who are being attacked regularly and have a track record of dealing with it rather than those who have no clue.
IP Spoofing
131–136 of 136 posts
Re: IP Spoofing
#132Earlier quoted context omitted.
Currently DDoS requires insecure hardware. If it didn't, we're one step closer to fixing it.
This statement is simply not true.
Currently, DDoS doesn't require compromised hardware, because of spoofing.
But if there were no spoofing, compromised hardware would be a requirement, and we're one step closer.
Re: IP Spoofing
#133Re: IP Spoofing
#134Earlier quoted context omitted.
Warning: Someone's cranky. It's a technical talk. It's much better to hear from people who are being attacked regularly and have a track record of dealing with it rather than those who have no clue.
sure except their paper just describes the issue and their solution is "pay us money". Not really up to the same standard as even a bad academic article, more like the paid talk track at a conference, you know, the kind lots of people avoid.
You can pay them, you can do it yourself, you can pay someone else, but at least you have options.
Re: IP Spoofing
#135Re: IP Spoofing
#136Earlier quoted context omitted.
This sounds great in principle, but it breaks down in practice. From the article, 27% of ISPs still allow spoofing on their networks. This is mostly due to them being smaller, regional ISPs without the expertise or staff to figure out how to do this. I hear you saying "just blackhole them until they figure it out," but it's not that easy. In many cases, the small regional ISP is the customer of a larger ISP, who is t…
You use netflow to identify the offender of course!