‹ BackHN Continuity

Thread

Show HN: I created a BGP-based blackhole system that you can set up in minutes

7 points · 10 comments · jkalbfeld

Loading the complete thread in the background. This saved snapshot is available now. Refresh

  1. fanthus · · focus · HN ↗

    [dead]

  2. RationPhantoms · · focus · HN ↗
    Your 4. is incorrect. Traffic does not get dropped upstream.
    1. jkalbfeld · · focus · HN ↗
      You're right. I fixed the copy to clarify its functionality. The blackhole feed doesn't actually sit in your traffic path; it tells your own router what to drop by creating longer CIDRs. Traffic still reaches you over your real ISP connection same as always - your router just can't send an ACK reply back, so it kills the handshake and prevents brute force attacks. If you also set up uRPF (covered in our setup docs), it goes a step further and drops their packets on arrival instead of just failing your reply. In this case, since we're not a transit provider, preventing volumetric attacks can be a little bit tricky since we're not actually in your upstream. However, it is possible to ETL chain data and generate a filter list. I figured at this price point, volumetric protection is a little bit hard to implement.
  3. smw · · focus · HN ↗
    I guess the real question here is what happens if my service _does_ get attacked by a volumetric DDoS? Do you immediately stop advertising?
    1. BrianGragg · · focus · HN ↗
      The statement above: It doesn't do volumetric protection against DDoS
    2. jkalbfeld · · focus · HN ↗
      Since you wouldn't be running transit through us, the traffic would still reach you, and you can use uRPF to block it in-situ.
  4. 112233 · · focus · HN ↗
    Hopefully upstream peers will use RPKI properly. It would be sad if this actually worked.
    1. BrianGragg · · focus · HN ↗
      I don't think RPKI will do anything to stop threats or DDOS attacks that happen currently. It should stop rogue route updates though.
      1. 112233 · · focus · HN ↗
        It will, however, stop projects like these from blacholing IP ranges belonging to others
        1. jkalbfeld · · focus · HN ↗
          It's not blackholing anything for anyone other than the subscriber, so this doesn't cause a block for anyone who isn't participating
    2. jkalbfeld · · focus · HN ↗
      RPKI is great, and I use it for everything except for two /24's that I got pre-ARIN. However, RPKI won't help with the situation where some kind of compromised host is worming its way through the internet running nmap against everything. Most of the IP addresses showing up in our dragnet are in fact announced by the very ISPs that own them. Most of these do not appear to be bogons.
  5. furqanashraf777 · · focus · HN ↗

    [dead]

  6. avajesh · · focus · HN ↗

    [dead]

  7. stavdavid · · focus · HN ↗

    [dead]

  8. avajesh · · focus · HN ↗

    [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.