ietf-asrg
[Top] [All Lists]

Re: [Asrg] Implementing IPv6 DNSBLs

2010-11-28 12:35:32
On Sun, Nov 28, 2010 at 12:56 PM, Daniel Feenberg 
<feenberg(_at_)nber(_dot_)org> wrote:

There is the further point that while it is possible to maintain a "badness"
list in a 32 bit space, it isn't really possible to maintain such a list in
128-bit (or even 64-bit) space, especially when the bad guys don't have to
keep track of which addresses they have already used.

I very much subscribe to this point of view. The futility of
"enumerating badness" in 128-bit-space was what originally led me to
push whitelisting with dnswl.org (which we are only now slowly
adapting to IPv6, but that's another story).

Accepting mail only from IPv4 will be the norm and will not result in any
lost mail, even far into the future.

As much as I support the above, I have my doubts about this. Of
course, not having the toolset on IPv6 as you are used to on IPv4 will
slow down the adoption. IMO, it makes sense to define a proper
protocol now, while adoption is still low, and people will need to
upgrade their systems anyway.

From my experience with dnswl.org I can tell that a proper way to
lookup range (as opposed to sending queries for consecutive IPs) would
make sense in IPv4 as well.

The protocol need not be based on DNS, although it has been proven to
be actually quite useful for the task.

-- Matthias
_______________________________________________
Asrg mailing list
Asrg(_at_)irtf(_dot_)org
http://www.irtf.org/mailman/listinfo/asrg

<Prev in Thread] Current Thread [Next in Thread>