North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: EC2 and GAE means end of ip address reputation industry? (Re: Intrustion attempts from Amazon EC2 IPs)

  • From: Suresh Ramasubramanian
  • Date: Sun Jun 22 21:15:52 2008

On Mon, Jun 23, 2008 at 1:13 AM, Steve Gibbard <[email protected]> wrote:

> Likewise, anybody blocking EC2 would miss out on whatever bad stuff might be
> coming out of EC2, but would miss out on being able to access services
> hosted there as well.  Would they miss it more than they'd miss their
> friends on GMail?  That seems far from guaranteed.

SMTP blocks, when most of what's on EC2 doesnt actually originate
email?   Access to it would be over http which isnt firewalled.  Or
maybe ssh gets firewalled off.

Death by a thousand access lists. Ouch.

This simply means there must be a lot more effort - from their
upstreams, and from their peers (not in a "network sense" as much as
"large network operators who are of a sufficient size to talk to
amazon and ensure that they're heard".   To convince them that some
filtering at their end, and implementation of abuse handling best
practices would be a good idea.

--srs