Calvin I am sensing a bit of misdirected hostility from you. If you are
angry at Valve for not dealing with weapon skins, I understand. But this is
a separate and even bigger problem that affects multiple games and is even
better at draining players from legitimate servers.

This leaves way too much room for false positives because of people with
> awful connections.


No it doesn't because the number will be compared with their own ping. If
they have a bad connection, it will show up in both their a2s_info pings
and in-game pings. It can also be averaged over a period of time. The
warning or server ban can also be localized to the player and not be a
global ban.

And as I said I am sure Valve is smart enough to figure out a better
solution.

The location function for that does not send any packets to the
> destination, it estimates the location by route. (Did you even read this
> before linking it?) Leaves room for false positives.


Yes I read it, and will give Valve more information to figure out if a
server is spoofing pings.

"I did not say put 200ms servers and 10ms servers in the same category. If
> you want to argue the point I actually made, we can do that"


That is what you are actually saying. Say you rely entirely on sv_region
but filter out any server that has >100 ping. Anycast ping spoofers are
going to win because they will show up on sub 100 ping lists while normal
servers don't. Even if they fix sv_region it is not going to help because
geoip region filtering is already being used and the ping exploit is still
sending servers to the top.

You have zero understanding of how the DDoS mitigation aspect of this
> works. It's not the VPS, the VPS is just handling the bgp session, the
> network where the IP space is being announced is handling the mitigation
> before it ever reaches the VPS.
>

I think you need to take a deep breath and take some time to think instead
of writing a hasty reply in 8 minutes. Yes they have bought generic ddos
protection on top their VPS, but it is not going to stop anything but the
most basic attacks. They are still rely on these vpses to process packets
on a shared CPU. The VPS also needs to forward game packets to the actual
server. It needs to do more than just BGP.

And also as I said, they've opened a dozen server in games that they've
previously failed to get into before. They know ping faking works and are
aggressively taking advantage of it.
_______________________________________________
To unsubscribe, edit your list preferences, or view the list archives,
please visit:
https://list.valvesoftware.com/

Reply via email to