Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How exactly? You can authenticate sender by sending a special confirmation token back.


How does one get removed from the block list?

Say some IoT device that half of households own gets compromised and turned into a giant botnet. The news gets out and everyone throws away that device. Now they are still blocked over a threat that doesn't exist anymore... doesn't seem like a good situation for anyone.

I'd imagine that the website owners that want the attack stopped will soon want to figure out how to get traffic back since they need users to pay the bills.

Whats to stop someone from just making an app that participates in an attack when connected to public(ish) wifi networks and participating in attacks long enough to get those all shut off from major sites?

How does this stop entire ISPs from getting shut off when the attackers have managed to cycle through all the IP pools used for natting connections? (e.g. the Comcasts of the world that use cg-nat to multiplex very large numbers of people to very small numbers of IPs)?


> How does one get removed from the block list?

We can add an "accept" packet that lifts the ban.

Also, how do you remove yourself from blacklist when banned by Google or Cloudflare? I guess here you use the same method.

> Say some IoT device that half of households own gets compromised and turned into a giant botnet. The news gets out and everyone throws away that device. Now they are still blocked over a threat that doesn't exist anymore... doesn't seem like a good situation for anyone.

Not my problem. Should have thought twice before buying a vulnerable device and helping criminals. As a solution they can buy a new IP address from their ISP.


As much as I half-wish there was something like this, it does sound like email spam blacklists all over again.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: