[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] Re: If the IPv6 ORPort can't be reached, will clients/relays fall back to the IPv4 ORPort?



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hello.

Marco Moock wrote:
> Build an escalation system.
> E.g. a single IPv6 will be blocked first, if more come from the same 
> /64, the entire /64 is blocked.
> If more come from the same allocation (either use /48 or even bigger if 
> you can query the BGP data) to block the entire ISP.

The problem with that is that someone with an /80 in that /64 could get
everyone else on that /64 blocked, which could be used as a way to target
specific people by getting them kicked off their guard.

For a commercial spam filter, it makes sense to treat every /64 as an
individual, but it's quite exploitable. I assume that's why toralf's
script will fall back to blocking based on /128 otherwise.

Regards,
forest
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCal8UyAAKCRAw+TRLM+X4
xoo8AQC/p10//qpdse1v9tSPckjqyisbnZ47gKKi3v9qrzcT/QEA55Ikn8b9FYtr
PNrfcPgJC1sWBmWtzXeXsZYz53wC6AI=
=ED+4
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx