|
|
|
|
|
by mjevans
2562 days ago
|
|
The real reason this isn't available to most relates to today's DDoS supporting Internet. Today everyone has to use a CDN to even try to defend against such attacks; and all they do is bulk filter the attack out while degrading the end user transparency of the service. Under 'load' some websites have to load an active filter page and execute code on the clients to authenticate that it's a valid client, rather than an attacker. The proper solution is to identify compromised devices and isolate them from the Internet. For hosts under attack to use a side channel to the ISPs routing the packets to ask them: "Please do not send anything from X to me for a bit; unless they satisfy to you that a user is in control." The request should be 'signed' by an end user key, authenticated by their ISP, and filtering should begin at the edge of that ISP. If they feel it necessary, they too can send a request to their ISP. Until this escalates to the backbones. Then it can press further back, down to the compromised node. That would allow infected end users to be quarantined, informed, allowed to download security updates and some other limited website interactions (manufacturer websites for updated firmware, some after-market firmware sites/tool sites like OpenWRT/DD-WRT/Linux distros, etc). Fix the DDoS issue, also fix the home upload bandwidth issue, and you too can host your own family photos/videos. |
|
The “home upload bandwidth issue” is “it's not a thing consumers demand, and we have business-class service for people who do have a need forit.”
I'm not sure what there is to solve...