Hacker News new | ask | show | jobs
by wmf 5501 days ago
Has route blackholing been tried yet? It seems like it would be pretty effective.
2 comments

Yes, it has been tried. But it is impractical, because of collateral damage:

- Many sites are hosted on massively shared hosts. Blocking those IPs will cause a lot of services to be unreachable, not just the one to be blocked.

- People find you with your domain name, not your IP, so a service could avoid filtering by switching subnets every day and just keep updating the DNS entry. After a certain time, the govt will be blackholing a large part of the internet.

It is. Remember when Pakistan blocked half the world from being able to access Youtube in 2008?[1]

(Though that was more incompetence by network engineers than legitimacy of the method)

[1] http://www.ripe.net/internet-coordination/news/industry-deve...