nanog mailing list archives
RE: dsl providers that will route /24
From: "David Schwartz" <davids () webmaster com>
Date: Thu, 29 Mar 2001 18:40:08 -0800
On Thu, 29 Mar 2001 15:08:24 PST, David Schwartz said:So long as spoofing is possible, you cannot be sure where an attack came
And spoofing is possible because people don't filter.
No, spoofing is possible because the protocol has no source authentication capability.
from unless you can either log it at its source or trace the stream to its source. That's the problem, and filters don't fix that.
So we shouldn't filter at the source because we can't fix the problem unless we're filtering at the source?
I never said people shouldn't filter. I've always maintained that filters are a useful tool. Filters just don't solve this particular problem.
Or are you saying that because seat belts fail 1% of the time, we shouldn't use them to help in the other 99% of the crashes?
No. I'm saying that so long as spoofing is possible without detection, you can never be sure where an attack is really coming from without cooperation from the source network. These are real problems, and filtering doesn't solve them. DS
Current thread:
- RE: dsl providers that will route /24, (continued)
- RE: dsl providers that will route /24 Jason Slagle (Mar 29)
- RE: dsl providers that will route /24 David Schwartz (Mar 29)
- Re: dsl providers that will route /24 Eric A. Hall (Mar 29)
- RE: dsl providers that will route /24 David Schwartz (Mar 29)
- Re: dsl providers that will route /24 John Payne (Mar 29)
- Re: dsl providers that will route /24 Eric A. Hall (Mar 29)
- RE: dsl providers that will route /24 David Schwartz (Mar 29)
- RE: dsl providers that will route /24 Greg A. Woods (Mar 29)
- Re: dsl providers that will route /24 Scott Francis (Mar 29)
- Re: dsl providers that will route /24 Valdis . Kletnieks (Mar 29)
- RE: dsl providers that will route /24 David Schwartz (Mar 29)
- RE: dsl providers that will route /24 John Fraizer (Mar 30)
- Re: dsl providers that will route /24 John Payne (Mar 29)
- RE: dsl providers that will route /24 David Schwartz (Mar 29)
- Re: dsl providers that will route /24 John Payne (Mar 29)
- RE: dsl providers that will route /24 David Schwartz (Mar 29)
- Re: dsl providers that will route /24 John Payne (Mar 29)
- RE: dsl providers that will route /24 David Schwartz (Mar 30)
- Re: dsl providers that will route /24 John Payne (Mar 30)
- RE: dsl providers that will route /24 David Schwartz (Mar 30)
- RE: dsl providers that will route /24 Charles Sprickman (Mar 29)