Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Your assumption is incorrect.


I would disagree. One of the problems of operating a VPN is that it is somewhat like operating a tor exit node: bad traffic is absolutely going to exit your infra. This means if you're renting VPSes or whatever you need a tolerant hoster.

For this reason a large part of Mullvad's infrastructure is hosted by M247 Ltd. If you simply block that ASN you will block quite a large part of Mullvad. You can block the ASN by using one of the myriad services that allow you to query all the IP blocks assigned to an ASN.

It's also possible to simply enumerate all their servers. They have an API.

You might not get it all, but you can block a significant percent.


The fact you could do it, doesn't necessarily mean that you WOULD do it. In my experience, the kind of mitigation you're talking about is seldom enforced (except Cloudflare, perhaps, and pretty much anybody serious knows how to get around THAT.)


this ASN is also popular among most VPN providers so you block this ASN and you could possibly remove a lot of abuse

I've done it at work, this is on a blacklist of ASNs that require "extra" authentication




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: