Re: [IRC-Security] IRC collaboration tonight concerning IRC DNSBLs

Andy Smith <[email protected]>
Newsgroups gmane.network.irc.blitzed.general
Message-ID <[email protected]>
I am sorry to be so negative on this subject but I just hope you
will trust me that it is from bitter experience.

On Wed, May 26, 2004 at 10:51:28AM +0200, Rafael Stuhr wrote:
> trying to summarize the discussion so far:
> 
> - dnsbls
> 
> querying a dnsbl will usually return an A entry like "127.0.0.*" where * is the type of abuse,
> examples:
> 127.0.0.2 for sub7 servers
> 127.0.0.3 for fyle drones
> 127.0.0.4 for spam

All of those things ideally require a different approach to solve
them, but you seem to be proposing that they just be banned.

What will you do when you have 10,000 individual IPs for some drone
all from AOL?  Those users will keep cycling as they reboot their
computers, redial, get new IPs etc..  Some of you will then wish to
blacklist the entire of AOL's consumer IP network, but how many of
us are willing to close our doors to AOL users?  repeat for every
major domestic broadband provider in the developed nations of the
world.

Banning IPs from accessing IRC in order to exert pressure on ISPs
from their user base simply will not work unless some very large IRC
networks are on board.  And if this is not demonstrated to work then
no large IRC network wants to get on board.

How should karma be apportioned to the maintainers of this DNSBL?
If I spend 6 months being incredibly conservative and then one day I
decide to burn my karma to blacklist the entire IP space of
roadrunner for spamming, and every IRC network using this system
disconnects every roadrunner user, I have just destroyed your DNSBL
and ruined any reputation it had with the few ISPs that were
receptive to pressure from it.  Can you think of a way to ensure
that this never ever happens?  Because if it happened once then I
think that would be the end of the project.

When slashdot moderators screw up, someone's post gets removed from
view temporarily.  When a DNSBL the like of which you propose screws
up, people get thrown off irc and may not be able to get back on for
some time, may end up being told to talk to their ISP, and will end
up totally confused and likely to just not bother returning.  No ISP
will thank you for this, and there will always be other IRC networks
large and small for these people to go to.

Here's what I propose.  As a trial of this concept and whether it
can ever be made to work, we will tackle a trivial example of IRC
"abuse": design a DNSBL that punishes people who cycle through all
your channels typing !list (and equivalents) in each in order to
find fserves.

The DNSBL will accept input from multiple channels on multiple IRC
networks.  Our challenge is to find a way to accurately share
information on these !listers, in the face of possibly hostile
reporters.  What is actually done with the info is up to the users
of the DNSBL, but probably would not include refusing access to the
entire server/network, instead would be more like banning from
channels (or warning chanops).

If we end up with a system that detects !listers before they !list
and bans them from so many channels that it may cause clue to be
absorbed, then we will have demonstrated that a collaborative DNSBL
documenting IRC abuse is doable.  We could then try to expand the
scope to tackle real examples of abuse at the level of the server or
network instead of the channel.

If, on the other hand, we find that once the number of reporters
grows large enough the quality of the reports drops too low,
innocent people are getting identified as !listers, dynamic IPs are
becoming a problem, and your confidence in the DNSBL itself has
failed, then we will at least have some perspective on the issue
- without buggering our IRC networks backwards with a spoon in the
process.

Here is my second proposal:  if I came up with an API for you to
list what you are banning (network-wide), and why, and when that
expires or when it is removed, would a number of reasonably large
and technically competent IRC networks here use it to maintain an
accurate and up-to-date list of their Akills/GLINEs/etc.?  That way
it would be trivial for any of us to get the scoop on what a given
IP/host has been up to on many other networks.  While it may not
solve massive automated threats like drones, it would be incredibly
handy for spotting repeat offenders in other areas on an ad-hoc
informational basis.

I am talking about some sort of database, possibly DNS-based, where
once you start reporting your own administrative actions to it, you
also get to see the actions of every other reporting network, for
the purposes of sharing experiences regarding IP blocks and hosts,
for each network to do with as they please.  It literally is as
high-level as "tell me what you ban, and why you banned it".

-- 
http://freebsdwiki.org/ - Encrypted mail welcome - keyid 0xBF15490B

"My current provisioning rule is to have no more than 2 out of 3 upstreams in
 bankruptcy at any one time. Of course, we allow the 3rd to be near bankruptcy,
 with an occasional liquidity crisis."
 -- Ken Leland, nanog

_______________________________________________
public mailing list
public-Hb7ITwsGSD4lroQnaJEqWdi2O/[email protected]
http://lists.blitzed.org/listinfo/public
signature.asc (application/pgp-signature, 187 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (FreeBSD)

iD8DBQFAtGnUIJm2TL8VSQsRAvO7AKCbm+8pJsK5KG2uaNLCdm8+f0CxlQCgnF0U
ka0oNjNDD9lEP3n5rXije6o=
=YhKw
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.