DNS issues various

Daniel Senie dts at senie.com
Fri Oct 25 07:48:49 UTC 2002


At 02:59 PM 10/24/2002, Kelly J. Cooper wrote:
>On Thu, 24 Oct 2002 Valdis.Kletnieks at vt.edu wrote:
>
> > On Thu, 24 Oct 2002 18:01:44 -0000, "Kelly J. Cooper" 
> <kcooper at genuity.net>  said:
> >
> > > So, seven years of hardening hosts against SYN attacks.  Five years of
> > > trying to get people to turn off the forwarding of broadcast packets.
> > > Three years of botnets generating meg upon meg of crap-bandwidth.
> > >
> > > Where are the suuuuuper-geniuses?
> >
> > You know, most bars have bouncers at the door that check IDs.  Sure, 
> they're
> > not perfect, but the bartender can usually be pretty sure the guy 
> ordering a
> > beer is over 21. The average bar isn't run by a soooper-genius.  But 
> it's still
> > considered fashionable to let packets roam your network without an ID 
> check at
> > the door.
>
>Yeah and how's that working so far?

The Bouncer/Bartender who serve an underage person are subject to 
prosecution, and are liable if someone gets drunk and goes driving and gets 
into trouble.

We've had BCPs in place for some time on directed broadcast and ingress 
issues. I expect it will take lawsuits to get many people to get serious 
about implementing these. While it's up to lawyers and judges to decide if 
ignoring an industry Best Current Practice opens a company to negligence, I 
won't be surprised if I'm asked to testify for a prosecution in such a case.




More information about the NANOG mailing list