Tue Feb 28 01:23:11 UTC 2006

> So what is left as monetary BCP38 compliance pressure?

probably not needed.  with spoofing actually starting to occur
and becoming a problem, it will be worth the isps' time to
start to filter.  until now i it hasn't been.  the economics
are pretty simple.  what is needed is to make the amplification
attack / spoofing issues publicly visible, as opposed to the
old cult of the dns 3l33t.

but dns amplification attacks will continue to be a problem
for a long enough time that closing recursive servers also
has to be seriously considered.


