Comment Force ISP to reject spoofed trafic (Score 1) 336
It's a shame that ISPs are routing spoofed udp packets, like in DRDOS attacks and are not made liable for this.
When a fake UDP packet, spoofed with the source IP being replaced by yours, is sent to an amplifying system, like quake/cs/hl/codt server or a dns, then you get the answers... A lot.
Why the hell those guys route trafic issued from an IP that is not in their range ? It's a line of config in routers. (Not exactly rocket science like a friend of mine says)
Well simply because they make money out of upload trafic... Shame. Ok it would only solve the DDOS based on UDP spoofed packets, but it's not few.
Btw I like the ideas expressed here lf a license to use a computer. Something giving the basics at least. I also like the idea of a reputation system (we have one in our high security cloud) to ban the IPs doing carp tepeatidly, by blackholing them, after a neutral group of netadmins decides it.