It's sort of pathetic that our answer to trying to stop DDoS amplification attacks is to cripple public UDP services. It shouldn't be acceptable for an ISP to originate spoofed packets. There is absolutely no excuse for it, yet we continue to accept it as some kind of inevitability and treat symptom after symptom of the same root cause.