Re: Protecting exit-nodes by GeoIP based policy

On Mon, Sep 11, 2006 at 10:15:56AM CEST, glymr wrote:

Anyway, I've written the script, but I won't release it, since it
creates a vast amount of exit policy rules, which (I guess) would not be
acceptable :-/

In the native variant excluding all german subnets would be something
like 7000 lines of exit policies. Then I added some fuzzyness and also
filtered the IPs between two subnets, if the gaps between two ip-ranges
is $close enough. Still I had something like 3000 lines of exit policies
(for germany only). 

Either people will have to use really large sets of false positives (i.e.
filtering traffic even if the IP is not in the country they wanted), or
there'll has to be another way of doing this.

-- Lexi

