Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's a bandage on a broken limb approach. The problem is that we have naive routing protocols that trust every packet received. The various BGP fiascoes have shown that we need to rewrite the routing protocols with the assumption of distrust. Until that happens DDoS will always be the pain in the butt that's always been.


which is cheaper, uRPF everywhere or re-writing everything (aka forklift upgrade).

my gut says the former and not the latter. I could be wrong.


You sound like the kind of person who also thought everyone would voluntarily move to IPv6 in a timely manner.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: