7 comments

[ 3.2 ms ] story [ 24.3 ms ] thread
Funny. You know I'll just use the origin key from my residential proxy when connecting through the proxy, right? There is no way to stop the use of residential proxies, and every attempt to block them simply makes organized crime (who runs most residential proxy) richer.

"The attacker cannot generate a valid Origin Signature without the provider's signing key."

Either the devices that are physically at the proxy home can't generate valid Origin Signatures (making the whole system pointless as no traffic will ever pass through any ISP) or the client had to type the key into their devices, and when they do that they can also text it to the proxy client.

I think IETF will have to restrict the submission process (somehow), or just hide unreviewed drafts from their domain entirely.

The slop submissions using "IETF Draft" as a trick to gain legitimacy are getting more and more frequent. It's really sad to see.

I was expecting to be able to ding this general idea just based on the inability to route it in a scalable fashion. But there are provisions for a location and a provider id, which would allow for decent aggregation if set up properly.

So I'm left being generally concerned with larding up layer 3 with all kinds of additional semantics, but really the draft is so thin its difficult to really determine how feasible it would be to implement and deploy.

(comment deleted)