|
|
|
|
|
by warent
2185 days ago
|
|
It adds no information or value to the discussion by giving the hackers a nationality. If there was a statistic that the majority of hackers wore hoodies, would we be calling that out and saying "Attacked by hackers in hoodies?" Obviously not because their clothing has nothing to do with the fact that they're malicious. What's happening here is profiling and it doesn't work. Add that to the fact that there are of course bad actors in countries including the US who happen to have proxies in other countries. Geolocating the IP address tells us nothing. The largest botnets came from a variety of nationalities and are rarely Chinese. Conficker was allegedly from the Ukraine, and a Swede plead guilty. Alureon came from Estonia. Mariposa from spain. Stop with the emotionally-charged flame baiting based on shallow data and anecdotal information. |
|
Geolocating the origination points of an exploit is extremely useful. Your point of other countries using proxies being the prime reason. The simple fact is if China and Russia wanted to limit the number of attacks originating from their IP blocks they could do so. Since they more or less allow it to continue they are a common source of malicious traffic, and geo blocking will significantly reduce the number of attempted exploits you experience.