[lacnog] DDoS, ataques de amplificacion y BCP38

Drew Weaver drew.weaver en thenap.com
Mie Mar 27 18:06:50 BRT 2013


Sorry for the English but as long as BCP38 is optional it will have limited impact. Especially given the huge amount of money carriers make by transiting traffic which they know they should be dropping.

I think a better solution would be to somehow tag a packet with the _actual SRC_ ASN so that you can publicly shame companies that allow these things to happen.

If we stop paying transit providers to transit spoofed packets spoofed packets would disappear overnight. :)



Fernando Gont <fgont en si6networks.com> wrote:


On 03/27/2013 05:27 PM, Carlos M. Martinez wrote:
> El tema de los open resolvers es increible... como algo tan facil de
> corregir es completamente ignorado por la gente.
>
> ¿Que nos pasa?

Lo mismo que sucede con el despliegue de v6.

Tristemente, actitudes similares en aspectos no-tecnicos hacen que haya
gente que no tenga que comer, donde dormir, etc...

Abrazo,
--
Fernando Gont
SI6 Networks
e-mail: fgont en si6networks.com
PGP Fingerprint: 6666 31C6 D484 63B2 8FB1 E3C4 AE25 0D55 1D4E 7492




_______________________________________________
LACNOG mailing list
LACNOG en lacnic.net
https://mail.lacnic.net/mailman/listinfo/lacnog
Cancelar suscripcion: lacnog-unsubscribe en lacnic.net



Más información sobre la lista de distribución LACNOG