On 3/17/2015 9:22 AM, Ian Eiloart wrote:
That refers to registered domains, I think. What I had in mind was the size of
the name space. It’s vastly larger, surely? IPv6 is 2^128 (3.4x10^38), whereas
in any TLD, there are about 37^63 (6.2x10^98 or 2^328). And that’s before you
get to any subdomains: which are rather easier to obtain.
Easy to obtain, I suppose that depends on the registrar. Which is why it might
be useful to have a reputation tool based on registrar. I think some already
look for recent registrations.
Ian,
I'm not saying you're wrong... but blocking -OR- scoring points based on
the registrar is painting with very broad strokes.
Plus, is there even enough money in existance to register all those
domains? (or even a small fraction of them?
One good thing about domains is that they usually have less collateral
damage than shared IPs. And even while subdomains are virtually
unlimited, they come under the authority/responsibility of the domain.
And in cases where the subdomain's abuse is occassional, with many other
legit subdomains running off the same domain.. .at least then
individual subdomains can be surgically targeted. (again, with the
option of going after the whole domain if the abuse gets really bad and
the domain owner puts forth zero effort to fix the abuse)
But, on the other hand, things like DMARC and SPF and checking the
rDNS.. etc.. etc.. are STILL far more resource intensive than simply
checking the sending IP against local rbldnsd-hosted blacklists. These
other methods often require time consuming lookups to third party
authoritiative DNS servers which are often SLOW. (so IPv6 is still at a
disadvantage)
--
Rob McEwen
+1 478-475-9032
_______________________________________________
mailop mailing list
[email protected]
http://chilli.nosignal.org/mailman/listinfo/mailop