Hacker Newsnew | past | comments | ask | show | jobs | submit | rini17's commentslogin

It would have an edge if it had inbuilt protection against spoofing. However now that there are big actors that profit off DDoS mitigation....

Or any other feature genuinely lacking from IPv4. Merely having unique address for every grain of sand on the planet isn't enough.


Don't many botnets use compromised machines now? Protocol level mitigations wouldn't help that would it?

It would make blacklisting compromised networks easier at least.

> And before you go on objecting that a physical true RNG remains better than a could-theoretically-be-broken CSPRNG, understand that your random output often must have no detectable bias to be secure. That means a distribution so uniform you can’t detect a bias even after analysing 2^64 samples.

Why not, actually? I would think simple and trivially auditable HW RNG with, say, only 0.9 bits of entropy per output bit (raw! no whitening) is preferable to "perfect" but fragile algorithm.

Anything that requires the randomness in practice has enough overhead so that the 90% good entropy is not a problem. Failures caused by wrong assumptions and complications are.


being wrong and insisting on being wrong is

They should at least call the army right, as "Warsaw Pact army". Specifically the Fulda gap breach was not planned to be sparheaded by Soviet army but they would send Czechoslovaks first into the meat grinder IIRC.

Perhaps some of the uncertainty at that border arose from considering whether the troops ordered forward would go, and who would they shoot at if they did.

Many bots open new TCP connection for every request, which is incredibly wasteful but leads to easy filtering via ipt_hashlimit firewall rules. Browsers and other well behaved clients work fine with limit as low as 3 connections per minute per IP. It avoids the SSL handshake overhead too. YMMV of course, but worth trying out.

Your account can get terminated for any other random nonsense though. Happens all the time, with cloudflare, google, github, everywhere. Everyone just pretends that "this can't happen to me". You want cyberspace free from any "evil" state jurisdiction, nor "coddling" so this is what you get.


was this meant as a reply to someone else?


no it was reply to "i just dont want cloudflare ai-scanning my blog, seeing the word "DDoS" because i am in networking, and proactively removing my site from the internet."


The former cyber-libertarians are running the tech unicorns now. Ofc they would prefer you see them as John Galts lol. But they aren't that and they will defend freedom of cyberspace only as far as it aligns with their power and profit.


Since monopolies make stuff scarce and expensive, you basically want free market for violence, it should be be cheap and abundant?

And all the DDoS and crytocurrency extortions and scams should extend to meatspace too, and you would be okay with it because it's supposedly still better than what govts do?


If you have friends with some shared meaning then anything is easy.

Everyone else can get get strip mined for attention and croak, you don't care.


Good? You would need the dashboard climate controlled all the time otherwise the algae gets sterilised in the sun. On the other hand, if you park underground all day, must provide light otherwise it dies. Either way it will eat your battery in no time.

Such an idea might be a good startup pitch for gullible investors but won't survive clash with reality.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: