On Wednesday, August 11, 2004, 5:10:00 PM, Ryan Thompson wrote: > Rick Macdougall wrote to SpamAssassin list:
>> John Hardin wrote: >> >>> On Wed, 2004-08-11 at 14:57, Jeff Chan wrote: >>> >>>> Right now, each >>>> name server is doing about 50 to 60k bits per second of traffic. >>>> We expect that to go up at least an order of magnitude when >>>> SA 3.0 goes gold. >>> >>> Do you have a nice strong distributed DNS setup? Sure as shootin' you're >>> going to be the target of a DDOS. >> >> I can't comment on their ability to survive a DDOS like Spews and SpamCop >> regularly get, but a lot of us "Power Users" rsync the data and run our own >> local servers for quicker response, playing nicely with others (we do on the >> order of 1 million requests a day +/-) and to remove the DDOS against the >> public servers problem. >> >> I think if the DDOS scenario ever did appear, they could just move to an >> rsync only type of solution. > Fine for larger installations, but that probably wouldn't be realistic > for small admins, and rsync is *easier* to DDoS than DNS. It's quite a > resource-expensive protocol. > The more servers, the better. We have 28 name servers around the world, with some more in the works. We also have or will have multiple redundant rsync servers, and we do want larger installations to use rsync instead of the public name servers. Large installation means processing more than 100k messages per day. Jeff C. -- Jeff Chan mailto:[EMAIL PROTECTED] http://www.surbl.org/
