Funny. You know I'll just use the origin key from my residential proxy when connecting through the proxy, right? There is no way to stop the use of residential proxies, and every attempt to block them simply makes organized crime (who runs most residential proxy) richer.
"The attacker cannot generate a valid Origin Signature without the provider's signing key."
Either the devices that are physically at the proxy home can't generate valid Origin Signatures (making the whole system pointless as no traffic will ever pass through any ISP) or the client had to type the key into their devices, and when they do that they can also text it to the proxy client.
Just a reminder that anyone can put anything they want up as an IETF draft. It means nothing. Building in identity to a network protocol is a terrible idea. Even this IETF draft is better: https://www.ietf.org/archive/id/draft-meow-mrrp-00.html
I was expecting to be able to ding this general idea just based on the inability to route it in a scalable fashion. But there are provisions for a location and a provider id, which would allow for decent aggregation if set up properly.
So I'm left being generally concerned with larding up layer 3 with all kinds of additional semantics, but really the draft is so thin its difficult to really determine how feasible it would be to implement and deploy.
7 comments
[ 3.2 ms ] story [ 24.3 ms ] thread"The attacker cannot generate a valid Origin Signature without the provider's signing key."
Either the devices that are physically at the proxy home can't generate valid Origin Signatures (making the whole system pointless as no traffic will ever pass through any ISP) or the client had to type the key into their devices, and when they do that they can also text it to the proxy client.
The slop submissions using "IETF Draft" as a trick to gain legitimacy are getting more and more frequent. It's really sad to see.
So I'm left being generally concerned with larding up layer 3 with all kinds of additional semantics, but really the draft is so thin its difficult to really determine how feasible it would be to implement and deploy.