Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 04 Apr 2001 11:15:45 -0500
From:      Bob Martin <bob@buckhorn.net>
To:        Chuck Rock <carock@epconline.net>
Cc:        freebsd-isp@FreeBSD.ORG
Subject:   Re: Chasing the kiddies (was: Named Keep crashing)
Message-ID:  <3ACB48B1.2BE269CF@buckhorn.net>
References:  <001b01c0bd1b$0b242a20$1805010a@epconline.net>

next in thread | previous in thread | raw e-mail | index | archive | help
*This message was transferred with a trial version of CommuniGate(tm) Pro*
Chuck Rock wrote:
> 
> How about getting a license to put a machine on the public network so you
> have to abide by "rules" for security, and if you are shown to screw up, and
> not maintain your security, your license is revoked, and your pulic IP's are
> then taken out of routes so they can't be accessed until you prove your
> worthiness again, or someone fixes it.

Well, we sorta have that now. Everyone has an AUP. The problem begins
when admins are too overwhelmed to enforce them, or in the case of a few
tier 1 and tier 2 providers I won't name, the bean counters have
determined that there is more money in allowing "a few bad apples" than
there is in enforcing the rules.
 
> How many people are allowed to connect any computer they want to the public
> network, and cause harm to some or all the other users on that network.
> Kinda like driving a car, only the consequences aren't necesarily deadly.

It amazes me that people will spend serious money for a computer, but
won't go the extra short step of learning about what it is, and what it
can do. It would really be of great if every computer shipped with a
"Using this computer for dummies"

The real problem here is that the people causing the problem would pass
their "driving" test with flying colors... And would most likely find a
way to "drive" without a license anyway.

> If you misconfigure BGP, you can effective screw up a large part of the
> Internet, this kind of power should not be given lightly.

Interesting point. If it was as hard to get an internet connection as it
is to get an ASN, maybe things would be a little better.

It's the "simple" screw ups that bother me most. Like allowing ip
directed broadcasts. There are still entire class B networks that can be
used for Papa Smurf attacks. And the only purpose it serves is to help
the sysadmin figure out which IP's they are using.

> My 2 cents,
> Chuck Rock
> EPC
> 

-- 
Bob Martin, CTO
InterNet Unlimited
http://www.inu.net
mailto:bob@inu.net

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-isp" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3ACB48B1.2BE269CF>