Hacker News new | ask | show | jobs
by gbear605 1096 days ago
I interpreted that as having an implicit “by this step of the filtering process”, not as applying to the entire firewall.
1 comments

The purpose of the RFC is to simplify security on the Internet, make such decisions transparent, and to preserve clear separation of concerns between the layers. As such, the evil bit is supposed to be the only thing that a conforming device checks.

Otherwise, we're back to square 1, where you don't know what caused your packets to be dropped even though they are clearly and explicitly not evil!