That said, I hope he doesn't give up the search for an alternative method, even if it's stashing a box in a hidden part of the library.
That said, I hope he doesn't give up the search for an alternative method, even if it's stashing a box in a hidden part of the library.
https://cloud.google.com/free/docs/gcp-free-tier/
"Free Tier: All Google Cloud customers can use select Google Cloud products—like Compute Engine, Cloud Storage, and BigQuery—free of charge, within specified monthly usage limits. When you stay within the Free Tier limits, these resources are not charged against your Free Trial credits or to your Cloud Billing account's payment method after your trial ends."
There is a small catch though, getting a static IP for the instance is not free, and your egress traffic starts costing after you reach 1GB outgoing data use in a months time.
The cool thing is (afaict), getting a static IP and going over 1GB egress doesn't totally knock you out of the free tier, you just pay for the static IP and any data usage past 1GB. My setup ends up costing me under a dollar per month with a static IP and very light egress usage.
The performance of the machine is not great but it's also not terrible consider the cost. I pretty sure you could run a small website and some other services on it no problem.
That's my favorite part of Oracle's always free tier[1], in comparison to other offerings.
[1] https://docs.oracle.com/en-us/iaas/Content/FreeTier/freetier...
My understanding is that this would require a change to TCP/IP itself, and NATs make this system probably unworkable in IPv4. But it would result in a truly distributed ddos protection. This also brings to mind the nightmare scenario of exponentionally larger parts of the IPv6 space hoovered up to satisfy the needs of spammers. Imagine burning 1 ip address per message!
EDIT: Ok, I thought about this a bit... would it actually work? Would the packets just find another path, and actually end up using more network resources as they traverse successively longer routes?
There's a trust issue, too: how far up the chain do you propagate the signal "suspected abuse from this host"? How hard would it be to abuse this system to censor people you don't like?
I don't have a mathematical proof, just an intuition about how the graph (nodes are routers, links are routes) would change in time. Yes, the packets might find another path, at least at first, but each time the recipient signals rejection every intermediate goes dark. Eventually, the sender will be surrounded, at some radius, by dark nodes. The best case is if the bad sender is rejected very quickly.
>how far up the chain
All the way, as close to 100% as possible. I would want this to be part of TLS encrypted socket such that either side of the socket can signal unhappiness with the counterparty, and have that be respected. This should be difficult to spoof, so you'd have to pick a way to signal it within the TLS stream, and do packet inspection at the middleboxes. (I never said it would be an easy solution!)