‹ BackHN Continuity

Thread

Show HN: I created a BGP-based blackhole system that you can set up in minutes

7 points · 10 comments · jkalbfeld

  1. RationPhantoms · · focus · HN ↗
    Your 4. is incorrect. Traffic does not get dropped upstream.
    1. jkalbfeld · · focus · HN ↗
      You're right. I fixed the copy to clarify its functionality. The blackhole feed doesn't actually sit in your traffic path; it tells your own router what to drop by creating longer CIDRs. Traffic still reaches you over your real ISP connection same as always - your router just can't send an ACK reply back, so it kills the handshake and prevents brute force attacks. If you also set up uRPF (covered in our setup docs), it goes a step further and drops their packets on arrival instead of just failing your reply. In this case, since we're not a transit provider, preventing volumetric attacks can be a little bit tricky since we're not actually in your upstream. However, it is possible to ETL chain data and generate a filter list. I figured at this price point, volumetric protection is a little bit hard to implement.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.