Re: RTBH Support Across the Industry
Charles Monson via NANOG <[email protected]> Mon, 27 Jul 2026 15:17:31 -0500
| Newsgroups | gmane.org.operators.nanog |
|---|---|
| Message-ID | <CAAbPayLb=Dhj5NmsQBwcw_01e3nnToYkarq3=03Ex+MoX=rYWw@mail.gmail.com> |
> > Simultaneously we need to push harder to adopt uRPF to prevent spoofed attacks. > > I agree with you that better Flowspec adoption would be nice, and better anti-spoofing. But on the anti-spoofing point, I think the need for attackers to spoof IPs will go down in the coming years so I think this prevention mechanism drop in priority (this is an unfounded gut feeling, nothing backed by data) To back up this point, the majority of our subscriber base is FTTH with symmetric download/upload speeds between 100M-1G. In recent months we've observed a number of subscribers participating in DDoS attacks sending directly from their address to the victim IP. Further investigation revealed they had questionable "free" streaming boxes that had joined them to a residential proxy botnet, which seemingly decided to switch to DDoS activities after some time. Anti-spoofing is good, and mitigations should still be put in place, but it doesn't help much when a few tens/hundreds of compromised hosts can individually saturate their gigabit upload. Charles _______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/[email protected]/message/OYA3VCP3PGVUJPURTLZVZLY3X46A5ERF/