Re: [IRC-Security] IRC collaboration tonight concerning IRC DNSBLs
Andy Smith <[email protected]>
| Newsgroups | gmane.network.irc.blitzed.general |
|---|---|
| Message-ID | <[email protected]> |
I am sorry to be so negative on this subject but I just hope you will trust me that it is from bitter experience. On Wed, May 26, 2004 at 10:51:28AM +0200, Rafael Stuhr wrote: > trying to summarize the discussion so far: > > - dnsbls > > querying a dnsbl will usually return an A entry like "127.0.0.*" where * is the type of abuse, > examples: > 127.0.0.2 for sub7 servers > 127.0.0.3 for fyle drones > 127.0.0.4 for spam All of those things ideally require a different approach to solve them, but you seem to be proposing that they just be banned. What will you do when you have 10,000 individual IPs for some drone all from AOL? Those users will keep cycling as they reboot their computers, redial, get new IPs etc.. Some of you will then wish to blacklist the entire of AOL's consumer IP network, but how many of us are willing to close our doors to AOL users? repeat for every major domestic broadband provider in the developed nations of the world. Banning IPs from accessing IRC in order to exert pressure on ISPs from their user base simply will not work unless some very large IRC networks are on board. And if this is not demonstrated to work then no large IRC network wants to get on board. How should karma be apportioned to the maintainers of this DNSBL? If I spend 6 months being incredibly conservative and then one day I decide to burn my karma to blacklist the entire IP space of roadrunner for spamming, and every IRC network using this system disconnects every roadrunner user, I have just destroyed your DNSBL and ruined any reputation it had with the few ISPs that were receptive to pressure from it. Can you think of a way to ensure that this never ever happens? Because if it happened once then I think that would be the end of the project. When slashdot moderators screw up, someone's post gets removed from view temporarily. When a DNSBL the like of which you propose screws up, people get thrown off irc and may not be able to get back on for some time, may end up being told to talk to their ISP, and will end up totally confused and likely to just not bother returning. No ISP will thank you for this, and there will always be other IRC networks large and small for these people to go to. Here's what I propose. As a trial of this concept and whether it can ever be made to work, we will tackle a trivial example of IRC "abuse": design a DNSBL that punishes people who cycle through all your channels typing !list (and equivalents) in each in order to find fserves. The DNSBL will accept input from multiple channels on multiple IRC networks. Our challenge is to find a way to accurately share information on these !listers, in the face of possibly hostile reporters. What is actually done with the info is up to the users of the DNSBL, but probably would not include refusing access to the entire server/network, instead would be more like banning from channels (or warning chanops). If we end up with a system that detects !listers before they !list and bans them from so many channels that it may cause clue to be absorbed, then we will have demonstrated that a collaborative DNSBL documenting IRC abuse is doable. We could then try to expand the scope to tackle real examples of abuse at the level of the server or network instead of the channel. If, on the other hand, we find that once the number of reporters grows large enough the quality of the reports drops too low, innocent people are getting identified as !listers, dynamic IPs are becoming a problem, and your confidence in the DNSBL itself has failed, then we will at least have some perspective on the issue - without buggering our IRC networks backwards with a spoon in the process. Here is my second proposal: if I came up with an API for you to list what you are banning (network-wide), and why, and when that expires or when it is removed, would a number of reasonably large and technically competent IRC networks here use it to maintain an accurate and up-to-date list of their Akills/GLINEs/etc.? That way it would be trivial for any of us to get the scoop on what a given IP/host has been up to on many other networks. While it may not solve massive automated threats like drones, it would be incredibly handy for spotting repeat offenders in other areas on an ad-hoc informational basis. I am talking about some sort of database, possibly DNS-based, where once you start reporting your own administrative actions to it, you also get to see the actions of every other reporting network, for the purposes of sharing experiences regarding IP blocks and hosts, for each network to do with as they please. It literally is as high-level as "tell me what you ban, and why you banned it". -- http://freebsdwiki.org/ - Encrypted mail welcome - keyid 0xBF15490B "My current provisioning rule is to have no more than 2 out of 3 upstreams in bankruptcy at any one time. Of course, we allow the 3rd to be near bankruptcy, with an occasional liquidity crisis." -- Ken Leland, nanog _______________________________________________ public mailing list public-Hb7ITwsGSD4lroQnaJEqWdi2O/[email protected] http://lists.blitzed.org/listinfo/public
signature.asc
(application/pgp-signature, 187 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (FreeBSD) iD8DBQFAtGnUIJm2TL8VSQsRAvO7AKCbm+8pJsK5KG2uaNLCdm8+f0CxlQCgnF0U ka0oNjNDD9lEP3n5rXije6o= =YhKw -----END PGP SIGNATURE-----