Hacker News new | past | comments | ask | show | jobs | submit login

Pardon my lack of knowledge, is it possible to block all requests that originate from a particular country?



Not really, because your neighbor's security camera is likely participating in the attack. See "Mirai botnet" for example.


Also why it's called DDoS and not DoS.


I work in reliability and I've sat at the intersection of this question before.

Kind of, but not really. A lot of times you'll see UDP blocked from EMEA, which stops a good amount of attacks but doesn't solve the problem. It also creates problems for services that rely on UDP like VOIP. These days, even if the command originates from EMEA many of the participants are IOT devices that've been compromised - and those may live in the host country!

Blocking an entire country can do something, sometimes, but it also opens up a wormhole of optics when users who are not knowingly part of malicious activity complain they can't access a service that the rest of the world can. Of course, the host country that operates with a decent degree of CYA acts like they have no idea why someone would do such a thing.

Mitigating this stuff long term is often a game of 4D chess on a rotating board.


While the attack might be sponsored by one country, the servers often come from a wide number of places.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: